In Opal, you can use nested groups (also called “group-group propagation”) to add a group to another group and automatically sync memberships between the groups.
Use nested groups to easily manage access to resources while maintaining existing user group structures. You can:
Define requestable groups containing resources; for example, a group called Prod Resources, composed of prod AWS and PagerDuty resources
Define non-requestable groups containing users; for example, a group called Software Engineers pulled from an Okta group rule
From the Prod Resources detail page under Group Access, add the Software Engineers group as a nested group, and set an access duration
In this example, users in the Software Engineers group are then automatically granted access to resources within the Prod Resources group, and changes in group membership are automatically pulled from Okta.
You can also use nested groups to connect disparate groups that require access to the same resources, e.g., a Google Group and Okta group, two Okta groups, etc.