Permission groups bundle event and layer access. A user can belong to many groups; their effective access is the union across all of them. Groups can also inherit from each other (no cycles allowed). Layer access is a set of capabilities: Title (name visible), View (content visible), View sensitive (PII fields visible), Edit (content editable). Edit together with View sensitive makes sensitive fields editable too.
Name
Description
Members
Actions
Edit Group
Permission Audit
Pick an event and a layer to see which users have which access — and which permission group(s) granted it. Users are bucketed by their effective set of layer capabilities; users without event access drop into None.