---
title: Adding Permissions to Password Vault Groups
slug: kronpam-reference-guide-3-5-0/adding-permissions-to-password-vault-groups
description: Learn how to assign permissions to SAPM (Simplified Account Provisioning and Management) groups with this comprehensive guide. Understand the options to assign permissions at the group level, including the ability to extend them to sub-groups, accounts wi
docTags: 
createdAt: 2022-07-29T09:27:46.000Z
---

Permissions for Password Vault accounts can be assigned to user groups or users as well.

After each permission is assigned at a group level, you will be asked if you would like to assign the permissions to sub-groups or not. You can select **Yes** or **No** to apply the rights to sub-groups or not, respectively.  Permission can be given to the Group, the Group, and the accounts under it, or the Group Full Tree on the Password Vault  Group Tree.

To assign Permissions to Password Vault Groups:

1. Navigate to **Secrets**.
2. Open the **Vault** tab.
3. Right-click the desired group in the tree.
4. Select the **Permissions&#x20;**&#x6F;ption from the menu.
5. Assign the permissions to the groups, just like for individual accounts.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/8UHG_X5EIjNcnnGmIZY3x_image.png "Adding Permissions to Password Vault Group")

THIS ONLY: Apply Permission to this group only.

ONE LEVEL: Apply Permission to this group and accounts inside this group.

FULL TREE: Apply Permission to this group and all inherited subgroups and subaccounts.

