How to configure Group Members (sys_user_grmember) edit capability, so that only the Group Manager is able to Edit the Groups so as to Add/Remove members from GroupIssue <!-- div.margin{ padding: 10px 40px 40px 30px; } table.tocTable{ border: 1px solid; border-color:#E0E0E0; background-color: rgb(245, 245, 245); padding-top: .6em; padding-bottom: .6em; padding-left: .9em; padding-right: .6em; } table.noteTable{ border:1px solid; border-color:#E0E0E0; background-color: rgb(245, 245, 245); width: 100%; border-spacing:2; } table.internaltable { white-space:nowrap; text-align:left; border-width: 1px; border-collapse: collapse; font-size:14px; width: 85%; } table.internaltable th { border-width: 1px; padding: 5px; border-style: solid; border-color: rgb(245, 245, 245); background-color: rgb(245, 245, 245); } table.internaltable td { border-width: 1px; padding: 5px; border-style: solid; border-color: #E0E0E0; color: #000000; } .title { color: #D1232B; font-weight:normal; font-size:28px; } h1{ color: #D1232B; font-weight:normal; font-size:21px; margin-bottom:-5px } h2{ color: #646464; font-weight:bold; font-size:18px; } h3{ color: #000000; font-weight:BOLD; font-size:16px; text-decoration:underline; } h4{ color: #646464; font-weight:BOLD; font-size:15px; text-decoration:; } h5{ color: #000000; font-weight:BOLD; font-size:13px; text-decoration:; } h6{ color: #000000; font-weight:BOLD; font-size:14px; text-decoration:; } ul{ list-style: disc outside none; margin-left: 0; } li { padding-left: 1em; } --> This article demonstrates how to configure Group Members (sys_user_grmember) edit capability, so that only the Group Manager is able to edit (as in add/remove) members from the group. ReleaseAll releasesResolutionPlease keep in mind that this article falls beyond the scope of support as it is a customized implementation. Below are just suggestions for reference which we have provided here to help solve similar issues. Create (or modify) the three record ACLs for table sys_user_grmember as per below:1.1 Configure a READ ACL for sys_user_grmember table1.2 Configure a WRITE ACL for sys_user_grmember table1.3 Configure a DELETE ACL for sys_user_grmember2. All above ACLs can have the same script code as per below: var answer = false;if( (gs.hasRole('user_admin')) || (current.group.manager == gs.getUserID() ) ){ answer = true; } 3. Configure a CREATE ACL for sys_user_grmember, since adding group member involves the many to many relationship on the saved record when using slushbucket.Below is the code suggestion to make the CREATE ACL work: var answer = validate();function validate(){ if( gs.hasRole('user_admin') ) { return true; }else{ var manager = current.group.manager; if(manager !='' && manager == gs.getUserID()) { //check in current relationship return true; } else { //check in parent relationship var parentManager = parent.manager; var parentName = parent.name; if(parentManager == gs.getUserID() ) { return true; } } }}