|
| 1 | +--- |
| 2 | +title: Create and Manage Domain Groups |
| 3 | +description: Learn how to create and manage domain groups (domain security groups) to apply different permission rules to different sets of domain members. |
| 4 | +internalScope: Audience is Domain Admins. Covers creating and managing Domain Groups (Domain Security Groups) and what each group permission controls. Does not cover workspace-level rules configuration or troubleshooting user access issues. |
| 5 | +keywords: [New Expensify, domain groups, domain security groups, how to create domain group, restrict workspace creation, enforce workspace rules, require company email, preferred workspace, Expensify Card preferred workspace, domain permissions, Domain Admin] |
| 6 | +--- |
| 7 | + |
| 8 | +<div id="new-expensify" markdown="1"> |
| 9 | + |
| 10 | +*Workspaces > Domains > [Domain Name] > Groups* |
| 11 | + |
| 12 | +# Create and Manage Domain Groups |
| 13 | + |
| 14 | +Domain Groups, also called Domain Security Groups, let you apply different permissions and rules to different sets of domain members. This is useful when different teams or roles need different permissions, such as employees versus managers. |
| 15 | + |
| 16 | +Your domain must be verified before you can create Domain Groups. Learn how to [claim and verify a domain](https://help.expensify.com/articles/new-expensify/domains/Claim-and-Verify-a-Domain). |
| 17 | + |
| 18 | +--- |
| 19 | + |
| 20 | +## Who can use Domain Groups |
| 21 | + |
| 22 | +Only **Domain Admins** can create and manage Domain Groups. |
| 23 | + |
| 24 | +--- |
| 25 | + |
| 26 | +## Where to find Domain Groups |
| 27 | + |
| 28 | +1. Click the navigation tabs (on the left on web, on the bottom on mobile). |
| 29 | +2. Click **Workspaces**. |
| 30 | +3. Scroll below your workspaces list to find **Domains**. |
| 31 | +4. Click your domain. |
| 32 | +5. Click **Groups**. |
| 33 | + |
| 34 | +--- |
| 35 | + |
| 36 | +## How to create a Domain Group |
| 37 | + |
| 38 | +Follow the steps in **Where to find Domain Groups** above, then: |
| 39 | + |
| 40 | +1. Click **Create group**. |
| 41 | +2. Configure the group settings and permissions (see **What Domain Group permission settings control** below). |
| 42 | +3. Click **Save**. |
| 43 | + |
| 44 | +--- |
| 45 | + |
| 46 | +## What Domain Group permission settings control |
| 47 | + |
| 48 | +## What the Default group setting does |
| 49 | + |
| 50 | +Enable this if you want all new domain members to be automatically added to this group. Setting a Default Group ensures new employees receive the correct permissions immediately. |
| 51 | + |
| 52 | +## What Strictly enforce expense workspace rules does |
| 53 | + |
| 54 | +Use this to ensure workspace-level rules are followed before a report is submitted. Enabling Strictly enforce expense workspace rules ensures workspace rule compliance and prevents incomplete submissions. |
| 55 | + |
| 56 | +## What Restrict primary contact method selection does |
| 57 | + |
| 58 | +Enable this to require members to use their company email address to access Expensify. Restricting primary contact method selection prevents members from using a personal email to access their Expensify account. |
| 59 | + |
| 60 | +## What Restrict expense workspace creation/removal does |
| 61 | + |
| 62 | +Enable this to prevent members from creating or removing workspaces. Restrict expense workspace creation/removal ensures centralized workspace management and prevents employees from creating additional workspaces outside the company’s approved setup. |
| 63 | + |
| 64 | +## What Preferred workspace does |
| 65 | + |
| 66 | +Set a preferred workspace to automatically route a group’s expenses and reports to a specific workspace. This is helpful if different members use different workspaces and you want to reduce manual workspace selection. If you have multiple workspaces, use this to route a group’s expenses to the right workspace by default. |
| 67 | + |
| 68 | +## What Expensify Card preferred workspace does |
| 69 | + |
| 70 | +If a preferred workspace is set, enable this option to automatically post **Expensify Card** transactions to that workspace. This ensures transactions are routed correctly and reconciliation is simplified. |
| 71 | + |
| 72 | +--- |
| 73 | + |
| 74 | +# FAQ |
| 75 | + |
| 76 | +## What is the difference between a Domain Group and a Workspace? |
| 77 | + |
| 78 | +A Domain Group controls permissions and access settings at the domain level. A Workspace controls expense rules, approvals, and reporting settings. |
| 79 | + |
| 80 | +## Can a member belong to more than one Domain Group? |
| 81 | + |
| 82 | +No, each member can only belong to one Domain Group. |
| 83 | + |
| 84 | +## What happens if I set a Default group? |
| 85 | + |
| 86 | +New domain members are automatically assigned to that group, ensuring they receive the correct permissions immediately. |
| 87 | + |
| 88 | +## Does Preferred workspace move existing expenses? |
| 89 | + |
| 90 | +No. Preferred workspace applies to new expenses and reports going forward. |
| 91 | + |
| 92 | +</div> |
0 commit comments