These changes apply when upgrading to Onyx v4.7 or later. For older versions,
see Users and Groups before v4.7.
What’s Being Removed
The following legacy roles and settings are removed:- Curator role
- Global Curator role
CURATORS_CANNOT_VIEW_OR_EDIT_NON_OWNED_ASSISTANTSenvironment variable
What Replaces Curators
The new system uses two mechanisms:Group permissions
Permissions granted to a group. These apply organization-wide to every member of that group.
Group Managers
Management access granted to a specific user from a group detail page. This is scoped to that one group.
Before and After
The only default groups are Basic and Admin.
Custom groups can be created when you need additional permission sets.
Custom groups and configurable group permissions are an Enterprise Edition feature.
What Happens During Upgrade
The migration handles the core role conversion automatically:1
Admins move to the Admin group
Users with the legacy Admin role are added to the Admin group and keep full workspace access.
2
Basic users move to Basic
Users with the legacy Basic role are added to the Basic group and keep core workspace access.
3
Curators become Group Managers
Existing Curators and Global Curators are converted to Group Managers for the groups they managed.
Their scoped management access carries over.
4
Existing groups are preserved
Existing custom groups, group memberships, connectors, document sets, and agents are preserved.
5
Document access is unchanged
Search visibility continues to follow connector access settings: Private, Public,
and Auto Sync Permissions.
The automatic Curator conversion applies to groups that exist at upgrade time. For groups created later,
assign Group Managers manually from the group detail page.
What You Need to Check
After upgrading, review the following:- Former Curators and Global Curators are Group Managers of the expected groups.
- Users who need full administration are in Admin.
- Regular users are in Basic.
- Organization-wide permissions are granted only to groups that should have workspace-wide access.
- New groups have Group Managers assigned manually when scoped management is needed.
Common Migration Questions
What if we were not using Curators?
What if we were not using Curators?
If you only used Admin and Basic roles, there is little to review. Admin users move to Admin,
and Basic users move to Basic.
Do existing groups and resources change?
Do existing groups and resources change?
Existing groups, memberships, connectors, document sets, and agents are preserved.
The migration changes how management permissions are represented, not the resources themselves.
Can we recreate Curator-like behavior?
Can we recreate Curator-like behavior?
Yes. Make the user a Group Manager of the relevant group.
This gives scoped management over that group’s members and resources.
When should we use group permissions instead?
When should we use group permissions instead?
Use group permissions when the access should be organization-wide. For example,
grant Manage Connectors & Document Sets to an IT group only if that group should manage connectors and document
sets across the workspace.
What happens to API keys and service accounts?
What happens to API keys and service accounts?
Existing Admin API keys move with Admin access, and Basic API keys move with Basic access. After upgrading,
you can assign service accounts to groups for more granular access.