How Do I Create a SPA Admin Group?

A knowledge base article about How Do I Create a SPA Admin Group? provided by the UC Berkeley IT Service Hub - Knowledge Portal

Creating a SPA Admin Group

Creating a central admin group to populate multiple Special Purpose Account (SPA) groups allows a department to manage access efficiently. When a member is removed from the central admin group, they are automatically removed from all associated SPAs. This is a best practice for managing personnel transitions within a unit.

  1. Go to calgroups.berkeley.edu and log in.
  2. In the left-hand sidebar, navigate to My groups or My folders.
  3. Select the specific folder or group space where you wish to establish the admin group.

2. Create the Admin Group

  1. Copy the name of the folder/group you are currently in.
  2. Click the More Actions menu and select Create New Group.
  3. Group Name: Paste the name you copied and add the suffix -spa-admin.
    Example: edu:berkeley:org:deptname:myfolder-spa-admin
  4. Description: Enter a clear description, such as: "This is the group of people who are added to our departmental SPAs."
  5. Click Save.

3. Set Privileges and Membership

Within the newly created -spa-admin group, configure the following:

Assign Privileges

Add Members


Example Use Case and Best Practices

Use your new admin group as a nested member instead of adding individual users to specific SPAs. For example, if you create a new SPA, you can add the -spa-admin group as a Direct Member of that SPA's access group.

This allows you to add a new employee to every departmental SPA simultaneously just by adding them to the central admin group. Conversely, when someone leaves the unit, a single removal from the admin group revokes their access to all associated SPAs.

Crucial Best Practice: Do not use a standard SPA access group as your departmental admin group. Using a separate, dedicated admin group prevents the risk of ending up with an empty SPA access group, which can trigger the automatic suspension of the affiliated bMail account.