# Manage project users and groups

The two membership layers — organization members and project members — plus groups, the Project Manager and Stakeholder roles, and the Project Profile permission levels (Everything, Direct assignments, Nothing) that decide what members actually see.

Product: nucleus-one · Audience: system-administrator · Time: 25 minutes · Last verified: 2026-09-05

Canonical: https://help.ademero.com/nucleus-one/administration/manage-project-users-and-groups

**At the end of this guide, the right people are in the right projects with the right roles — and, just as important, the Project Profile permission levels are set so members see what they should and nothing more.**

Membership in Nucleus One has two layers. The **organization** is your company's tenant — being a member there means you exist. A **project** is where work happens — being a member there means you participate. Access is decided project by project.

## Add people to the organization

1. In the left navigation, choose **Manage Orgs** and pick your organization.

2. Open **Members**. The **Organization Members** list shows each person's name, email, when they were added, and whether they're an **Organization Admin**.

3. Click the **+** control, enter the person's **Email Address** in the **Add member** dialog, and click **ADD**.

4. Opening a member afterward gives you two switches — **Administrator** and **Disabled** — plus a checkbox list of projects to place them in directly. Organization admins don't get the project list: they can already reach everything, so per-project placement is moot.

Grant **Administrator** sparingly. It's the whole tenant — every project, every setting.

## Add people to a project

1. Open **Projects**, pick the project, and choose **Settings** > **Project Members**. (The Settings branch is visible to project admins — if you don't see it, you're not one for this project.)

2. Click **+**. The **Add project members** dialog takes one field, **E-mail(s)** — enter several addresses at once — then **ADD**.

3. To set roles, open a member. **Project Member Details** offers three switches:
   
   | Switch | What it does |
   |---|---|
   | **Project Manager** | The project's admin flag — can manage everything in the project, including these settings |
   | **Stakeholder** | Marks the member as a stakeholder for the project |
   | **Disabled** | Turns the membership off without removing it |
   
   The same dialog has a **Group** section — a **Member In Group** switch per group, so placement happens right where you're already editing the person.

*[Screenshot: The Project Members list with the Add project members dialog open]*

## Create groups

Groups live per project, under **Settings** > **Groups**:

1. Click **+**, name the group in the **Create a group** dialog, and click **CREATE**.
2. Open it (**Project Group Details**) to rename it or flip the **In Group** switch beside each member.

Name groups for the work, not the org chart — `AP Approvers` outlives `Karen's team`.

## Decide what members can access

This is the step that's easy to skip and shouldn't be: **Settings** > **Project Profile**, under the **Project permissions** heading. Two sections do different jobs:

- **Assignments** — who items can be *assigned to* (Tasks, Approvals, Folders): **Project members**, or **Anyone in the world**. Note the built-in exception: documents can be signed by anyone regardless.
- **Member access** — what non-admin project members can *see and use*, area by area:

| Area | Levels offered |
  |---|---|
  | Tasks | **Everything** / **Direct assignments** |
  | Approvals | **Everything** / **Direct assignments** |
  | Folders & documents | **Everything** / **Direct assignments** |
  | Assets | **Everything** / **Nothing** |

**Everything** means members browse the whole area; **Direct assignments** means they see only items assigned to them. Assets is the odd one out — it's all or nothing. Project Managers can manage everything regardless of these levels.

An **Other** section adds one restriction switch: **Disallow content removal by project members**.

Changes arm an **UPDATE** button, and confirming gets a real warning — **"Change permissions?"** — because the change has to propagate to every item in the project. Expect it to take some time on a large project; that's the propagation, not a hang.

> **NOTE:** These levels shape navigation itself. A member whose Approvals access is **Direct assignments** doesn't see a restricted approvals area — the area simply isn't offered beyond what's theirs. If someone reports a section "missing," check the Project Profile before anything else.

**Success check:** add a test (non-admin) member with **Direct assignments** on Folders & documents, sign in as them, and confirm they see only what's assigned to them — then assign one item and watch it appear.

## What's next

- [Migrate from Content Central to Nucleus One](https://help.ademero.com/nucleus-one/administration/migrate-from-content-central-to-nucleus-one)
- [Nucleus One SOX (Sarbanes-Oxley) compliance documentation](https://help.ademero.com/nucleus-one/compliance/nucleus-one-sox-compliance-documentation)
