A unit for managing permissions across multiple IAM users together.
Assigning a policy to a group rather than to individual users keeps permission management consistent and easy to audit. When someone changes roles, only their group membership needs to change.
© 2026 ITBGM