How to set group permissions and assign a group to a user in KSeFGPT
Create or edit a group, select the permitted operations, and assign the group to an active organization member. The access change takes effect immediately.
- Module
- Organizations
- Reading time
- 6 min
- Difficulty
- You could do this with your eyes closed :)
- Published
- August 11, 2026
- Author
- Rafał Zeidler
- Format
- Written guide
Written procedure
What you will do
You will configure a permission group in your KSeFGPT organization: select the operations its members can perform and save the changes.
You will then assign the group to an active user. From that point on, their access to the selected company's data and modules is determined by the combined permissions of all groups assigned to them.
Requirements
Before you start
First decide which tasks the user should perform. Grant only the permissions they need, especially for sending invoices, managing KSeF authorization credentials, or managing other organization members.
| Item | Requirement |
|---|---|
| Access | The organization owner or a member with the organization:manage_groups permission. |
| Organization | An organization created for the correct company. Select that company in the account switcher before you start. |
| User | An active organization member who has accepted the invitation. Groups cannot be changed for the owner or a person with the Invited status. |
| Access scope | A list of the user's tasks, such as viewing invoices, sending them to KSeF, importing, viewing analytics, or managing contractors. |
| Starting point | After signing in, select the correct company and open Organization. |
| Time required | About 3 minutes. |
| Important effect | A group permission change takes effect immediately for all its members, not only the user referenced in this instruction. |
Open the organization for the correct company
In the account switcher, select the company in which you want to set group permissions. Then select Organization in the main navigation.
If you manage several companies, check the selected organization name before changing any groups. Groups and members belong to a specific organization.
Open Groups
Select Groups in the top navigation of Organization. You will see the groups, their member counts, assigned permissions, and the Edit and New group buttons.
The system group named Zarząd has full access and cannot be deleted. For an employee, accounting team, or external accounting office, it is usually safer to create a separate group with narrower permissions.
Create a group or set its permissions
To configure an existing group, select Edit in its row. To create a new one, select New group, enter its name, and choose a color that makes it easier to identify in the user list.
Under Group permissions, select the permitted operations. You can search by permission identifier or its description. Each permission is selected independently.
| Area | Permission | What it allows |
|---|---|---|
| Organization | activities:read | View the history of user actions in the organization. |
| Organization | organization:invite | Invite users to the organization. |
| Organization | organization:manage_groups | Manage groups, their permissions, and member assignments. |
| Company and KSeF | companies:create | Create new companies. |
| Company and KSeF | credentials:manage | Add and remove KSeF authorization credentials. |
| Company and KSeF | settings:edit | Edit company settings. |
| Invoices | invoices:read | View invoices. |
| Invoices | invoices:send | Send invoices to KSeF. |
| Invoices | invoices:import | Import individual invoices. |
| Invoices | invoices:bulk_import | Bulk import invoices. |
| Other modules | chat:use | Use the AI chat. |
| Other modules | automation:manage | Manage automations. |
| Other modules | analytics:read | View analytics. |
| Other modules | contractors:manage | Manage contractors. |
| Other modules | integrations:manage | Manage integrations. |
Save the group
Check the group name and selected permissions. For an existing group, select Save. For a new group, select Create group.
After a successful save, Group changes saved or Group created appears. The Groups list will display the current permission identifiers.
If the edited group already has members, the new permissions take effect for them immediately. Before removing an important permission, check the member count displayed next to the group name.
Return to the user list
Select Settings in the top navigation of Organization. On the Users card, find the email address of the active member whose access you want to change.
Group editing is disabled for the owner and for a person with the Invited status. You can select groups when inviting a user; further changes become available after they accept the invitation.
Assign the group to the user
In the Groups column, select add next to the correct user. Select the prepared group from the list. The assignment is saved immediately—there is no separate Save button.
After it is added, the group name appears next to the user's email address. The list under add contains only groups that this person has not yet joined.
To remove this group's permissions from the user later, select × next to its name. Remember that the same permissions may still be granted by another group assigned to the user.
Check the action history
Select Activity in the top navigation of Organization. The log shows recorded operations for the selected company: the user's email address, the action, and the date and time it occurred. An unsuccessful or blocked operation is additionally marked as rejected.
After completing this instruction, the list should include updated a group and added a user to a group. This lets you check who changed the organization member's access and when.
The organization owner can access the log automatically. Another member can open Activity only if at least one of their groups includes activities:read.
Final state
Check the result
On the Users card, the assigned group name should appear next to the member's email address. Under Groups, that group's member count should increase and the user's initials should appear next to it.
The new access works correctly if, after selecting the organization in their account, the user can open the permitted modules and perform the operations granted by the group while all other operations remain blocked.
Diagnostics
If something does not work
Compare the displayed status or message with the table below.
| Symptom | Likely cause | What to do |
|---|---|---|
| New group and Edit are not visible | Your account does not have organization:manage_groups for the selected company. | Ask the owner or organization administrator to grant permission to manage groups. |
| You cannot open Activity | Your account does not have activities:read for the selected company. | Ask the owner or organization administrator to assign you to a group that includes activities:read. |
| add is not visible next to the user | This is the owner, the person still has the Invited status, or you do not have organization:manage_groups. | Select an active member. If the invitation is pending, ask the user to accept it. |
| The group is not listed under add | The user already belongs to that group. | Check the group labels displayed directly next to their email address. |
| Operation failed appears after the change | The group or member assignment could not be saved. | Keep the page open. Check your connection and organization:manage_groups permission, then try again. |
| The user still cannot perform the required operation | The group does not include the correct permission, or a different organization is selected. | Check the active company, open Groups, select Edit, and compare the required identifier with the selected permissions. |
| The user has more access than expected | They also belong to another group that grants additional permissions. | Check all group labels next to the user and remove the unnecessary assignment with ×. |
What next
Regularly review the members of groups that include invoices:send, credentials:manage, organization:invite, or organization:manage_groups because these permissions allow higher-impact operations.
If the user is not yet an organization member, follow How to add a user to an organization in KSeFGPT.
Configure your team's access in KSeFGPT
Sign in, set the group permissions, and assign the group to an active organization member.