Access Groups
An access group is a team space — it decides which features (and therefore which data) a group of people can reach. Add someone to an access group and they can see everything that access group has; that one rule drives most of “who can see what” in Ronja. An access group grants access — it isn’t a folder your data lives in. The mechanics: users are members of access groups, access groups have features, and you can see a resource if you can reach the feature that owns it through one of your access groups.
The Default access group
Section titled “The Default access group”Every organization starts with one access group, badged “Default”. It has two conveniences switched on: every user is automatically a member, and it shares all organization features. It can’t be deleted. Many small teams never need another access group — you create more when different groups should see different things.
Membership
Section titled “Membership”Admins manage who belongs to an access group. The Members tab lists everyone in the organization with a per-row Add/Remove toggle (you can’t remove yourself), and the Users & Access matrix handles bulk changes across all access groups at once — see Manage users and roles.
Two access-group-level toggles change the rules, and both are admin-only:
- “EVERYONE IS A MEMBER” (the access group’s All users flag) — every current and future user in the organization is automatically a member. While it’s on, individual Add/Remove is disabled; new hires get access without an invite step.
- “All-users admin access group” — in the product’s words: “When enabled, all access group members get admin privileges within this access group. They can upload files, manage features, configure table access, and manage members.” Useful for a high-trust team space; the elevation applies inside that access group only, and never extends to creating or deleting access groups.
Features: what an access group provisions
Section titled “Features: what an access group provisions”An access group reaches a feature when an organization-scope feature is attached to it. Attachment is managed on the Features × access groups map on the Shared features page, where each cell shows Full, Partial, or None:
- Full — members see everything in the feature.
- Partial — a restricted attachment: only the specific resources an admin grants.
- None — not attached.
Each access group also has a “SHARE ALL FEATURES” switch that attaches every organization feature automatically — including ones shared later.
Sharing a feature into an access group
Section titled “Sharing a feature into an access group”Features aren’t handed over to a single access group. A creator promotes a feature to Organization scope (an admin approves), and an admin then attaches it to the access groups that should reach it on the Features × access groups map — or leaves the access group’s “share all features” switch to pick it up automatically.
What access groups don’t own
Section titled “What access groups don’t own”Explorations do not belong to access groups. A conversation connects to a team only when its owner shares it — with individual people or with an access group, in which case everyone in that access group can open it.
Deleting an access group
Section titled “Deleting an access group”Only Admins can delete an access group. Deletion is a soft delete: the access group moves to the trash for 30 days, but members lose access immediately and its automations pause. Restoring within the window brings it back and resumes the automations; after 30 days it’s purged permanently. See Restore from trash.
Still unsure when to reach for an access group versus a feature? See What’s the difference?.