> For the complete documentation index, see [llms.txt](https://docs.couchdrop.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.couchdrop.io/administration/user-and-group-management.md).

# User and Group Management

Learn about managing Users and Groups in Couchdrop

## Overview

Users and Groups control who can access Couchdrop and what they can access.

You can create Users to provide individual people, partners, applications, or external systems with access to Couchdrop. Groups let you organize multiple users together so access can be managed more consistently across your account.

User and Group management is available via the [Admin Panel](/administration/admin-panel-and-user-mode.md).

## Users

A User represents an individual identity that can access Couchdrop.

Depending on how the user is configured, they can be given access to specific folders and storage locations and can connect using supported transfer methods such as SFTP. User settings can also control authentication, file permissions, network access, expiry, and other security controls.

For example, you might create separate users for:

* Employees who need access to Couchdrop
* Customers or business partners exchanging files over SFTP
* Applications or automated systems
* Teams that require access to specific folders or storage locations

Using separate user accounts means you do not need to share administrative credentials with people or systems that only require file access.

Users can also be provisioned individually, through bulk import, through the Couchdrop API, or through SCIM for ongoing identity lifecycle management.

## Groups

Groups provide a way to organize users together.

Instead of managing users entirely as individual identities, groups can be used wherever Couchdrop supports assigning access or management responsibilities to multiple users together. For example, Couchdrop Mailboxes can be assigned to specific users and groups through **Mailbox Managers**.&#x20;

Groups are useful when several users perform the same role or need access to the same Couchdrop resources.

## Administrative Access

Users should be treated separately from Couchdrop administrative access.

For example, an SFTP user can be given access to a specific folder without being given administrative access to the Couchdrop tenant. Couchdrop recommends avoiding the use of an owner account for SFTP connections because owner accounts have elevated permissions.

This separation allows administrators to provide the access required for a particular person, partner, or system without exposing account-wide administration.
