Skip to main content

10. Teams

Setting up teams - allowing users to be grouped into roles, and then assigning them to Resource Groups to define the access and capabilities

Teams are how access is organized on MontBlancAI. Users never receive roles or permissions directly — everything flows through a team. Teams also determine who receives operational notifications and which resource groups a user can work with.

The Default team

Every organization has exactly one Default team. All members of the organization are automatically part of it — you can't opt out — and it carries the organization's Default Role, which grants the standard product permissions every member should have. This is the baseline; other teams add to it.

Owners can choose which team acts as the default.

How teams grant access

A team can grant access in three ways:

  1. Default roles — roles attached to the team that apply to every member, automatically including people who join later. This is the recommended way to manage access at scale.

A user's total access is the union of everything granted across all of their teams.

Teams and resource groups

For asset-related permissions, teams are also the unit of scoping: resource groups list which teams can access them. A team's asset permissions only apply to assets in resource groups that the team has access to. See Resource Groups for details.


Teams and notifications

Operational alerts (threshold violations, anomalies, machine connectivity) are delivered to the teams responsible for the affected equipment. Each team has per-notification-type settings that administrators can switch off if a team shouldn't receive a given type. See Notifications and teams.


Microsoft Entra ID (Azure AD) synchronization

If your organization has connected Microsoft Entra ID, teams can be linked to Entra ID groups and their membership synchronized automatically. Synced teams are typically paired with a Read Only role by default; you control what additional roles they carry.

Use 'Sync From Azure' to sync all teams/groups you have assigned to the Enterprise Application in Entra ID:

Use 'Refresh' action icon to sync the Team memberships for specific team:


Who can manage teams

Action

Who

View teams

Any member of the organization

Create, edit, delete teams

Owners, admins, or holders of the team management permission

Add / remove team members

Owners, admins, or holders of the team management permission

Attach roles and permissions to teams

Owners, admins, or holders of the team management / role management permissions

Configure team notification settings

Owners, admins, or holders of the team management permission

Tips for structuring teams

  • Mirror your real-world structure: shifts, departments, production lines, or plants all make good teams.

  • Combine a team with a resource group per plant/line to give each local crew full control of their own equipment and read-only visibility elsewhere.

  • Keep the Default team's role minimal and use dedicated teams for elevated access — it keeps permissions auditable.

Did this answer your question?