Get
Returns a user group by its global id. Requires the https://devx.{environment}.oleria.io/read scope.
Authorizations
OAuth 2.0 client-credentials flow. Request an access token from the token endpoint and send it as Authorization: Bearer <token>.
Path Parameters
Global id of the user group.
Response
The user group.
An Oleria UserGroup object represents a group in an enterprise SaaS application, identity provider, or directory service e.g. Okta, PingOne, ActiveDirectory, GitHub, Salesforce, or ServiceNow
This is an application-specific string indicating the type of group being represented by the UserGroup object. Typically this is the information used to derive the UserGroupType specified in the UserGroup.type field
"EmailDistributionList"
An identifier (unique to the integrated or assigned application) for a UserGroup object represented in the Oleria system. Oleria converts these identifiers to global ids so they can be unique in the context of the global system graph. It is important for this identifier to be based on an underlying persistent and reusable application or identity provider id so connections to the object are robust to metadata changes and other relevant operations
"team:T_kgDOLL0doQ (GitHub), 37d284db-1d76-4587-aa78-5a33cfcc021f:member (SharePoint)"
The name (title) of the group which is typically informative of the group's purpose for granting access to resources (see also description)
1"AI Maintainers"
The ObjectMetadata structure defines metadata that applies to every object and relationship, and is usually managed by the system that receives the data
The following group types are supported:
- Built-in groups are used to represent system-defined groups that can be leveraged by the application administrator to give access to resources via roles and permissions assigned to the group. Account membership in built-in groups is typically explicit
- Custom groups are created by administrators or users (with appropriate privilege) to give access to resources via roles and permissions assigned to the group. Account membership in custom groups is typically explicit
- Dynamic groups are created by administrators or users (with appropriate privilege) where membership in the group is dynamic and based on a defined set of attributes evaluated either periodically or at access control evaluation
- Modeled groups are an Oleria representation of an RBAC group like concept in the application typically used to represent concept like Everyone
- Sync groups are synchronized between an identity provider and enterprise application (or directory)
Built-in, Custom, Dynamic, Modeled, Sync "Custom"
object metadata supersets object metadata with platform enrichment provenance — the enrichment version and the time the record was generated
AuthenticationRequirements are used to specify authentication requirement configuration for Oleria integrated applications as described by their corresponding IntegratedApplication object
AuthorizedLocationPolicy is used to specify locations authorized for use by accounts, groups, roles, employees, departments, etc.
An identifier (unique to integrated application) for an Account object represented in the Oleria system. Oleria converts these identifiers to global ids so they can be unique in the context of the global system graph. It is important for this identifier to be based on an underlying persistent and reusable application or identity provider id so connections to the object are robust to metadata changes and other relevant operations
"user:U_kgDOB7P6Rg (GitHub based on node identifier), 838439349399 (Google Workspace based on user id), user:wiz-inc-4db1c46901 (GitHub based on app slug)"
Federation information used when specifying an EntityIdentifier
The date the group was created
"2024-05-02T03:17:34.948Z"
The description of the group
"AI Maintainers"
Federation information used when specifying an EntityIdentifier
The directoryEntryId is emitted when this UserGroup object is synced with an UserGroup object emitted by a directory. The id here should match the synced UserGroup.id
Federation information used when specifying an EntityIdentifier
The directoryProviderId indicates the DirectoryProvider defining the directory sync relationship for this group
The email address associated with the group
"ai-maintainers@oleria.com"
Label tags associated with the group, particularly when used for data classification and sensitivity targeting
An identifier (unique to integrated application) for an Account object represented in the Oleria system. Oleria converts these identifiers to global ids so they can be unique in the context of the global system graph. It is important for this identifier to be based on an underlying persistent and reusable application or identity provider id so connections to the object are robust to metadata changes and other relevant operations
"user:U_kgDOB7P6Rg (GitHub based on node identifier), 838439349399 (Google Workspace based on user id), user:wiz-inc-4db1c46901 (GitHub based on app slug)"
Federation information used when specifying an EntityIdentifier
The date the group was last modified
"2024-05-02T03:17:34.948Z"
Federation information used when specifying an EntityIdentifier
An identifier (unique to the integrated application) for a ObjectDirectory object represented in the Oleria system. Oleria converts these identifiers to global ids so they can be unique in the context of the global system graph. It is important for this identifier to be based on an underlying persistent and reusable application or identity provider id so connections to the object are robust to metadata changes and other relevant operations
"repo:R_kgDOLL0doQ (GitHub based on repository node identifier), 1BUxdX4M-H7X8GKRgTjprJS8fjY_Ij1giE82lQlny2kc (Google Drive based on file id)"
An array of profile key-value pairs extending the schema of the UserGroup object
An array detailing all participants in a provisioning relationship with this UserGroup
An application-specific tag representing the group information data source
"OrgTeams"
AuthenticationRequirements are used to specify authentication requirement configuration for Oleria integrated applications as described by their corresponding IntegratedApplication object
AuthorizedLocationPolicy is used to specify locations authorized for use by accounts, groups, roles, employees, departments, etc.
Normalized version of the email found in UserGroup.Email
Cached count of resource instances this user group can access, including nested (Contains) descendants. Values above 1000 may be approximate.

