User Groups
Apply monthly usage limits to every member of an identity provider group across the organizations you choose.
User Groups lets enterprise admins manage Factory settings by the groups that already exist in your identity provider (IdP). Configure a group once, choose the organizations it applies to, and every member of that group picks up the setting. Membership stays in your IdP: when someone joins or leaves a group there, their Factory settings follow.
Today a group can carry one setting: a monthly usage limit per member.
Before you start
- You are an Owner of the enterprise root organization. User Groups is an Admin Console page, so local organization admins and sub-organization owners do not see it.
- Directory Sync is configured under Security & Identity.
- The groups you want to use are assigned to the Factory application in your IdP and have completed at least one sync.
Until the first sync completes, the page shows No groups synced from your identity provider with a shortcut to set up Directory Sync.
How group usage limits resolve
Every user's effective monthly limit comes from three tiers. The first tier that is set wins.
| Order | Tier | Applies when |
|---|---|---|
| 1 | Individual override | An admin set a limit for this specific user. |
| 2 | Group limit | The user belongs to at least one group with a limit in this organization. If they belong to several, the highest group limit applies. |
| 3 | Global user limit | Neither of the above is set. Without a global limit, usage is unlimited. |
A few consequences of this order:
- A group limit replaces the global user limit, so it can be lower or higher than the global limit.
- An individual override always wins, even when it is lower than the user's group limit. Use it for exceptions.
- Belonging to more groups never lowers a user's limit. The most generous mapped group applies.
- Group limits apply per organization. A group can have a limit in one organization and none in another.
Limits are resolved when a request is made. Saving, changing, or removing a group limit writes nothing to individual users. Members pick up the change on their next request.
Configure a group
- 1Open User Groups
In settings, open Admin Console → User Groups. The list shows every synced group with its current configuration.
- 2Set the monthly usage limit
Select the edit button on a group's row to open Configure for that group. Under Monthly usage limit, enter the limit per member in millions of credits. For example,
50means 50,000,000 credits per member each month. - 3Choose organizations
Select Next, then check each organization where the limit should apply. The root organization is selected by default for a new configuration. If your enterprise has only one organization, this step is skipped and the limit applies to the root.
- 4Review and save
If the save changes an existing configuration, a warning lists each organization whose limit changes or is removed. Review it, then select Save.
One save applies the same limit to every selected organization. Organizations you leave unchecked lose any configuration this group had there, and members in those organizations fall back to their individual override or global limit.
When a group's limits differ across organizations (for example, because they were set through the API), the list shows the range, such as Varies by organization: 20M to 50M credits per member each month. Opening the group starts with an empty limit, so the next save sets one value for every selected organization.
Remove a configuration
Open the group and select Remove configuration. This removes the group's limit from every organization in the hierarchy. Members fall back to their individual override or the global user limit on their next request.
Groups removed from your identity provider
If a group is deleted or unassigned in your IdP while it still has a configuration, it stays in the list as <group id> (not in directory) and sorts last. Its limit no longer reaches anyone, because membership is no longer synced. Remove the configuration to clean it up.
See group limits for each user
Group limits also appear wherever per-user limits are managed. In Settings → Usage, select Manage under individual user limits:
- The Group filter lists users whose effective limit comes from a group. Each row shows the group name and limit, for example Engineering · 20.00M credits.
- Expand a user to see the resolution order: individual override, each group tier, and the global user limit, each marked Applies, Superseded, or Not set.
- Use Set individual override in the expanded row to give one user an exception to their group limit, or Remove override to return them to it.
Enforcement, the manager usage table, and weekly usage summary emails all use the same resolution, so the limit a user sees is the limit that is enforced.
Membership sync
Factory reads group membership from Directory Sync. Adding or removing a user from a group in your IdP updates their Factory groups through Directory Sync events, and a periodic reconciliation corrects any drift. Group limits are keyed by the group's stable directory ID, so renaming a group in your IdP does not break its configuration.
Group membership affects only the settings configured on User Groups. Roles still come from your group-to-role mapping.
Manage group limits with the API
Managers can read and set group limits for their organization through the Organization API:
GET /api/v0/organization/usage/limits/groupsreturns each mapped group with its directory name and limit.PUT /api/v0/organization/usage/limits/groupsmaps up to 100 groups per request. Each entry takes a directorygroupIdand alimitin credits (minimum 1,000,000). Passnullas the limit to unmap a group.
curl -X PUT https://api.factory.ai/api/v0/organization/usage/limits/groups \
-H "Authorization: Bearer $FACTORY_API_KEY" \
-H "Content-Type: application/json" \
-d '{"groups": [{"groupId": "directory_group_01EXAMPLE", "limit": 50000000}]}'The API applies to the organization the API key belongs to. Use User Groups in the Admin Console to configure several organizations at once.
Audit trail
Every group limit change, from the Admin Console or the API, is recorded in the audit log under usage limits, with one event for each organization whose group limit changed.
FAQ
Related resources
Manage directory, organizations, billing, and identity for the enterprise.
Configure SSO, Directory Sync, and group-to-role mapping.
Create organizations and manage global and per-user usage limits.
Review usage limit changes and other administrative activity.