- Introduction
- Access control and administration
- Account management
- Accessing capabilities
- Role-based access control (RBAC)
- Access control for group-based project roles (Automation Cloud)
- Managing projects
- Governance
- Quotas
- Licensing
- Frequently asked questions

IXP overview guide
When you assign project roles to groups, the users part of those groups can access any projects the groups are added to. This means the users can view the data within those projects, which might not be appropriate for a large group of users, especially in regulated industries. For more details, check Understanding the data structure and permissions.
As a best practice, when you use single sign-on (SSO), segregate groups at relevant and appropriate access levels. For example, if only a limited set of users should access a specific project, create per-project groups to provision access to that project. Otherwise, unauthorized people might access the data.
If strict segregation is required and data must not be shared across teams, consider using a separate Automation Cloud tenant.