Overview
This guide walks you through creating user permission groups in CX so you can assign access by role instead of managing permissions user by user. By setting up structured, role-based groups, you streamline onboarding, reduce permission errors, and maintain least-privilege access across your organization. Completing this workflow ensures users inherit the correct Read, Write, or Admin access based on their job function. The result is a scalable, audit-friendly permission structure that supports efficient retirement plan operations.
Common Uses
When you are setting up CX for a new firm or restructuring access controls.
During onboarding of multiple team members who share similar responsibilities, such as Operations or Relationship Managers.
When preparing for an internal audit and standardizing access by role.
When cleaning up inconsistent or outdated user-level permission overrides.
How To
Identify Role-Based Access Needs
Review your firm’s job functions, such as Operations, Relationship Managers, Compliance, and Administrators.
Determine what level of access each role requires in key modules (Read, Write, or Admin).
Document the intended access structure before creating groups.
Important: Design groups around job function, not individual users, to avoid duplication and permission drift.
Navigate to Users and Groups
Log into CX with Admin access.
Open the Users and Groups section from the main navigation.
Select the Groups tab to view existing permission groups.
Confirm you are in the correct workspace before making changes.
Create a New Group
Click Create Group.
Enter a clear, role-based group name (for example, “Operations – Write Access” or “Relationship Managers – Read Only”).
Add a brief description outlining the intended job function and access scope.
Use consistent naming conventions so access reviews are easier to manage later.
Save the group to proceed to permission configuration.
Configure Group-Level Permissions
Open the newly created group.
Assign the appropriate permission level for each module:
a. Select R (Read) for view-only access.
b. Select W (Write) for create and edit access.
c. Select Admin only if full access across current and future permission areas is required.Review each module carefully to ensure access aligns with the role’s responsibilities.
Avoid granting Admin for convenience. Use the lowest level of access that allows the role to perform required tasks.
Save your changes.
Reopen the group to verify that all permission settings were applied correctly.
Assign Users to the Group
Navigate to the Users tab.
Open an existing user profile or invite a new user.
Assign the user to the appropriate group.
Save changes.
Confirm the user now appears as a member of the selected group.
Expected result: The user inherits all permissions assigned to the group.
Validate Effective Access
Ask the user to log in, or test access using your internal validation process.
Confirm the user can access only the modules and actions appropriate for their role.
Verify both visibility (Read) and editing capabilities (Write) where applicable.
If access is not correct, review group-level permissions before making any user-level overrides.



