Reading Time: < 1 minute
A female individual sorting color coordinated stacks of paperwork.

Grouper

Grouper is an enterprise group and access management system that serves as a core component of the InCommon Trusted Access Platform. 

Primary Capabilities:

Simplifies access management by letting you use the same group or role in many places in your organization

Automates changes to access privileges as a person’s role changes

Empowers the right people to manage access

Institutions can leverage Grouper to:

 

Coordinate Collaboration

Grouper helps collaboration happen. You can set up groups, roles, and permissions for many purposes, such as populating and administering standing committees, ad hoc research teams, departments, or classes. Key collaborative applications — mailing lists, wikis, calendars, etc. — can use this group, role, and permission information to make authorization decisions.

Centralize Access Management

Grouper provides enterprise-wide access control through a unified management platform. When personnel are added to or removed from groups, access privileges are automatically synchronized across all integrated collaborative applications, enabling streamlined administration from a single control point.

Key Business Benefits:

 

Operational Efficiency

Reduces deployment time and costs for new services while simplifying ongoing management through automated privilege updates as organizational roles evolve.

Enhanced Governance

Delivers comprehensive visibility into access permissions with detailed reporting capabilities, ensuring full transparency and regulatory compliance.

Seamless Integration

Designed for compatibility with existing access management infrastructure, enabling organizations to leverage current investments while expanding capabilities.

Scalable Role Management

Enables consistent application of group-based permissions across multiple systems and applications, eliminating redundant administrative tasks and reducing potential security gaps.

Grouper delivers enterprise-grade access governance with distributed control capabilities, enabling rapid and flexible provisioning integrations. The platform provides comprehensive auditing and reporting functionality to ensure complete visibility into access decisions—documenting the identity, rationale, timing, and methodology behind every resource authorization.

As an important component of the InCommon Trusted Access Platform architecture, Grouper manages attribute-based and role-based authorization services while maintaining auditable group memberships. The system leverages authoritative institutional data from systems of record to ensure access decisions remain aligned with organizational policies and current personnel status.