---
url: /process-functions/userSecurity-group.md
description: A security group and its model, object and element permissions.
---

# &#x20;Group&#x20;

A security group and its model, object and element permissions.

```js
const group = userSecurity.groups.get("Finance");
group.setModelPermissions("Sales Model", "READ_ACCESS");
```

## Constructor

Returned by [userSecurity.groups.create()](/process-functions/userSecurity-groups#create) and [userSecurity.groups.get()](/process-functions/userSecurity-groups#get). It can't be created directly.

## Overview

* **Access levels:** permissions use `"NO_ACCESS"`, `"READ_ACCESS"` or `"WRITE_ACCESS"`.
* **Object types:** object permissions use `"CUBES"`, `"CARDS"`, `"WORKVIEWS"`, `"DIMENSIONS"`, `"PROCESSES"`, `"SCHEDULES"`, `"TABLES"`, `"APPLICATIONS"`, `"MAPPINGS"` or `"VARIABLES"`.

## Methods

### getId `getId()`  {#getid}

Returns the group's id.

### getName `getName()`  {#getname}

Returns the group's name.

### isEditable `isEditable()`  {#iseditable}

Returns `true` when the group's name and permissions can be changed.

### isDeletable `isDeletable()`  {#isdeletable}

Returns `true` when the group can be deleted. Built-in groups such as the admin group can't be.

### rename `rename(newName)`  {#rename}

Renames the group. Returns `true` when the name changed.

| Parameter | Type | Description |
|---|---|---|
| `newName` | `string` | The group's new name. It must not already be taken. |

### delete `delete()`  {#delete}

Deletes the group. Returns `true` when it was deleted.

### getModelPermissions `getModelPermissions(modelNameOrId)`  {#getmodelpermissions}

Returns the group's access level for a model, as an object with the model's `id` and its `access_level`.

| Parameter | Type | Description |
|---|---|---|
| `modelNameOrId` | `string` | The model's name or id. |

### setModelPermissions `setModelPermissions(modelNameOrId, accessLevel)` {#setmodelpermissions}

Sets the group's access level for a model.

| Parameter | Type | Description |
|---|---|---|
| `modelNameOrId` | `string` | The model's name or id. |
| `accessLevel` | `string` | `"NO_ACCESS"`, `"READ_ACCESS"` or `"WRITE_ACCESS"`. |

### setAllModelPermissions `setAllModelPermissions(modelNameOrId, accessLevel)` {#setallmodelpermissions}

Sets the same access level for a model and every object and element in it.

| Parameter | Type | Description |
|---|---|---|
| `modelNameOrId` | `string` | The model's name or id. |
| `accessLevel` | `string` | `"NO_ACCESS"`, `"READ_ACCESS"` or `"WRITE_ACCESS"`. |

### getObjectPermissions `getObjectPermissions(modelNameOrId, objectType)`  {#getobjectpermissions}

Returns the group's access levels for one type of object in a model, such as every cube.

| Parameter | Type | Description |
|---|---|---|
| `modelNameOrId` | `string` | The model's name or id. |
| `objectType` | `string` | The object type. See the [list of object types](#overview). |

### setObjectPermissions `setObjectPermissions(modelNameOrId, objectType, objectKey, accessLevel)` {#setobjectpermissions}

Sets the group's access level for one object in a model.

| Parameter | Type | Description |
|---|---|---|
| `modelNameOrId` | `string` | The model's name or id. |
| `objectType` | `string` | The object type. See the [list of object types](#overview). |
| `objectKey` | `string` | The object's name or id. |
| `accessLevel` | `string` | `"NO_ACCESS"`, `"READ_ACCESS"` or `"WRITE_ACCESS"`. |

### getElementPermissions `getElementPermissions(modelNameOrId, dimensionNameOrId, hierarchyNameOrId)`  {#getelementpermissions}

Returns the group's access level for every element in a hierarchy, in hierarchy order. Each entry has the element's `name` and `access_level`. Returns at most the first 10,000 elements.

| Parameter | Type | Description |
|---|---|---|
| `modelNameOrId` | `string` | The model's name or id. |
| `dimensionNameOrId` | `string` | The dimension's name or id. |
| `hierarchyNameOrId` | `string` | The hierarchy's name or id. |

### setElementPermissions `setElementPermissions(modelNameOrId, dimensionNameOrId, hierarchyNameOrId, permissions)` {#setelementpermissions}

Sets the group's access level for specific elements in a hierarchy. Elements you don't list are left as they are.

| Parameter | Type | Description |
|---|---|---|
| `modelNameOrId` | `string` | The model's name or id. |
| `dimensionNameOrId` | `string` | The dimension's name or id. |
| `hierarchyNameOrId` | `string` | The hierarchy's name or id. |
| `permissions` | `object` | Each key is an element name and each value is its access level. |

### setAllHierarchyPermissions `setAllHierarchyPermissions(modelNameOrId, dimensionNameOrId, hierarchyNameOrId, accessLevel)` {#setallhierarchypermissions}

Sets the same access level for every element in a hierarchy.

| Parameter | Type | Description |
|---|---|---|
| `modelNameOrId` | `string` | The model's name or id. |
| `dimensionNameOrId` | `string` | The dimension's name or id. |
| `hierarchyNameOrId` | `string` | The hierarchy's name or id. Pass `null` or `""` to apply it to every hierarchy in the dimension. |
| `accessLevel` | `string` | `"NO_ACCESS"`, `"READ_ACCESS"` or `"WRITE_ACCESS"`. |

## Examples

### Rename or delete a group

```js
const group = userSecurity.groups.get("Example Group");
console.log("Group ID: " + group.getId());

const renamed = group.rename("Renamed Group");
console.log(renamed ? "Group renamed successfully." : "Failed to rename group.");

if (group.isDeletable()) {
    const deleted = group.delete();
    console.log(deleted ? "Group deleted successfully." : "Failed to delete group.");
}
```

### Model and object permissions

```js
const group = userSecurity.groups.get("Example Group");

group.setModelPermissions("Test Model", "READ_ACCESS");
console.log("Model Permissions: ", group.getModelPermissions("Test Model"));

group.setObjectPermissions("Test Model", "CUBES", "Test Cube", "WRITE_ACCESS");
console.log("Object Permissions: ", group.getObjectPermissions("Test Model", "CUBES"));

// The same access level for the whole model
group.setAllModelPermissions("Test Model", "READ_ACCESS");
```

### Element permissions

```js
const group = userSecurity.groups.get("Example Group");

group.setElementPermissions("Sales Model", "Geography", "Regions Hierarchy", {
    "North America": "WRITE_ACCESS",
    "Europe": "NO_ACCESS"
});
console.log("Element Permissions: ", group.getElementPermissions("Sales Model", "Geography", "Regions Hierarchy"));

// Every element in one hierarchy
group.setAllHierarchyPermissions("Sales Model", "Geography", "Regions Hierarchy", "READ_ACCESS");

// Every element in every hierarchy of the dimension
group.setAllHierarchyPermissions("Sales Model", "Geography", null, "READ_ACCESS");
```

## Related

* [Groups](/process-functions/userSecurity-groups): creates and finds groups.
* [User](/process-functions/userSecurity-user): adds users to groups.
