Resource Groups control where permissions apply. While roles define what someone can do (view equipment, edit thresholds), resource groups define which assets they can do it on — letting you scope teams to specific plants, lines, or areas of your operation.
What can be grouped
Resource groups contain assets from your hierarchy:
Sites
Areas
Lines
Equipment
Signals are not grouped directly — they follow the equipment they are assigned to.
The Master group
Every organization starts with a system-managed Master resource group that contains all assets. It always exists and can't be deleted, and every asset belongs to at least one group (the Master group by default).
Until you create custom resource groups, permissions simply apply organization-wide — you don't need to think about resource groups at all unless you want location- or line-based scoping.
How scoping works
Each resource group lists the teams that have access to it. When a user acts on an asset, MontBlancAI checks two things together:
Does one of the user's teams grant the required permission (through its roles or extra permissions)?
Does that same team have access to a resource group containing the asset?
Both must be true. This is what makes combinations like "full control of Line 1, read-only everywhere else" possible: put the user in a team that has editing roles and access to the "Line 1" resource group, while their organization-wide team only carries view permissions.
Creating assets is scoped the same way: to add a new asset into a resource group, you need the add permission through a team that has access to that group. You can't create assets in parts of the hierarchy your teams can't manage.
Who can manage resource groups
Two permissions govern resource groups:
View resource groups — part of every member's baseline access; lets users see the resource groups their teams have access to.
Manage resource group access — deliberately not part of the baseline. Holders see every resource group and can create new ones. They can assign assets to a group and control which teams have access to it when one of their teams already has access to that group, or when the group has no teams yet. Grant this only to the people who administer your access structure.
Organization owners and admins can always manage every resource group (and are never restricted by them). If you can't change a group, its controls are shown read-only, with a note explaining why.
Example setup
A company with two plants might configure:
Resource group | Contains | Teams with access |
Master (system) | Everything | Org-wide teams (e.g. Default team) |
Plant Vienna | Vienna site and everything under it | Vienna Operations, Vienna Maintenance |
Plant Munich | Munich site and everything under it | Munich Operations, Munich Maintenance |
Give the maintenance teams a full-control role and the operations teams an operate/view role. Each crew then fully manages its own plant, while everyone retains the organization-wide visibility granted through the Default team.



