Creating a SPA Admin Group
Creating a central admin group to populate multiple Special Purpose Account (SPA) groups allows a department to manage access efficiently. When a member is removed from the central admin group, they are automatically removed from all associated SPAs. This is a best practice for managing personnel transitions within a unit.
1. Navigate to Your Folder Space
- Go to calgroups.berkeley.edu and log in.
- In the left-hand sidebar, navigate to My groups or My folders.
- Select the specific folder or group space where you wish to establish the admin group.
2. Create the Admin Group
- Copy the name of the folder/group you are currently in.
- Click the More Actions menu and select Create New Group.
- Group Name: Paste the name you copied and add the suffix
-spa-admin.
Example:edu:berkeley:org:deptname:myfolder-spa-admin - Description: Enter a clear description, such as: "This is the group of people who are added to our departmental SPAs."
- Click Save.
3. Set Privileges and Membership
Within the newly created -spa-admin group, configure the following:
Assign Privileges
- Navigate to the Privileges tab.
- Click Add Members and search for the group name you just created (e.g.,
yourgroup-spa-admin). - Check the boxes to assign Update, Read, and View privileges.
- Click Add.
Add Members
- Navigate to the Members tab.
- Click Add Members and enter the UIDs of the staff members in your department who should have administrative access to your SPAs.
Example Use Case and Best Practices
Use your new admin group as a nested member instead of adding individual users to specific SPAs. For example, if you create a new SPA, you can add the -spa-admin group as a Direct Member of that SPA's access group.
This allows you to add a new employee to every departmental SPA simultaneously just by adding them to the central admin group. Conversely, when someone leaves the unit, a single removal from the admin group revokes their access to all associated SPAs.
Crucial Best Practice: Do not use a standard SPA access group as your departmental admin group. Using a separate, dedicated admin group prevents the risk of ending up with an empty SPA access group, which can trigger the automatic suspension of the affiliated bMail account.