Creating employee groups

You must have the Manage Employees permission to set up an employee group. By default, users with the role of App User Admin have this permission.

To create an employee group

  1. Click the Employees tab in the Compliance Accelerator client.

  2. Click New Employee Group at the top of the window.

  3. In the right pane, type the name of the group and a brief description.

  4. If you want to synchronize the group with the user account information held in an external source like Active Directory, check Automatically synchronize. Then type the required details.

    The options are as follows:

    Active Directory search, or Domino LDAP search

    Lets you specify the appropriate search filter and search root. If the target employees are in various parts of your organization, their user accounts may be in different areas of the directory. By using a search with one or more search filters, you can find and automatically add these users.

    An LDAP search filter can be based on any number of custom or standard attributes, but it must target user objects. You can combine multiple filters to find the members for a department. For example, you can enter the following to find all users whose department attribute is set to UK Equities:

    (&(objectCategory=person)(department=UK Equities))

    In the Search Root box, type the Distinguished Name for the search root. This name identifies where in the directory hierarchy to start the search. For example, if your directory spans multiple countries, you can set the root to the UK organizational unit by entering the following:

    LDAP://OU=UK, DC=MyCompany, DC=com

    Check Search whole tree to include the members of nested groups.

    Active Directory container

    Lets you type the name of the Active Directory container.

    In the ADsPath box, type the Distinguished Name of the Active Directory container that holds the users to add to the employee group. For example, suppose that the UK Equities department points to this organizational unit container:

    CN=Equities, OU=UK, DC=MyCompany, DC=com

    You can enter the following to add all the employees in the department to the group:

    LDAP://CN=Equities, OU=UK, DC=MyCompany, DC=com

    Check Search nested containers to include the members of nested containers.

    Windows group or distribution list, or Domino group or distribution list

    Lets you type the name of a group in the form domain_name\group_name. The group may or may not be held in your directory. If you do not use Active Directory or a Domino directory, you can only update the display name of employee profiles by synchronizing. You need to enter additional employee information manually.

    If you want to synchronize the employee group with a Domino group or distribution list, you must enable the following Domino LDAP attributes for anonymous access in Lotus Domino Administrator:

    • cn

    • dominocertificate

    • mail

    • maildomain

    • member

    • objectclass

    See the Lotus Domino documentation for instructions on how to do this.

    By default, Compliance Accelerator synchronizes employees and groups every four hours and every time that the Enterprise Vault Accelerator Manager service starts. However, you can change this setting.

  5. If you want to add employees to the group manually, click the Members tab and then click Add. Then select the employees from the list.

    You can select multiple adjacent employees by holding down the Shift key while clicking the first and last employee in the range. To select multiple nonadjacent employees, hold down the Ctrl key while clicking the required employees. Click OK when you have finished.

  6. Click Save.

More Information

Setting Compliance Accelerator system configuration options

About the Compliance Accelerator permissions

Editing employee groups

Deleting employee groups