You've created content that isn't for everyone — maybe it's for managers only, a single region, or just your own team while you preview a release. To restrict content in uStudio, you assign it to a group: a defined set of users who are allowed to see it.
There are two ways to build a group, and the difference comes down to who keeps the member list up to date:
- Synced groups — your company's identity system maintains the list automatically.
- Manually managed groups — you maintain the list yourself in the UMC (uStudio Management Console).
Your company's identity system is the software your IT team uses to manage employee accounts and logins (examples include Okta and Microsoft Entra). It already knows things like each employee's department, role, and location, and it can sort people into groups automatically based on those attributes. Synced groups let uStudio borrow those groups, so you never have to maintain a member list yourself.
Which path is right for you?
- Is this a large audience defined by something your company already tracks — department, region, job level? Use a synced group.
- Is this a small or one-off audience — a handful of named people, a pilot group, admins previewing content? Create the group yourself in the UMC (manually managed).
Synced groups come in two flavors — SCIM and SAML — and which one you have is determined by your organization's configuration, not by preference. Contact the uStudio Customer Success team (success@ustudio.com) to confirm which applies to you.
At a glance
| Synced via SCIM | Synced via SAML | Manually managed in the UMC | |
| Best for | Large or changing audiences (e.g., "all sales managers") | Large or changing audiences, when SCIM isn't available | Small, hand-picked audiences (e.g., a preview team) |
| Who maintains the member list | Your identity system, automatically | Your identity system, automatically | You, in the UMC |
| What's required | Company login (single sign-on) plus SCIM provisioning — a behind-the-scenes connection you won't see as a user | Company login (single sign-on) without SCIM provisioning | Nothing — works out of the box |
| IT involvement | Yes — IT sends the group to uStudio | Yes — IT sends the group; you then map it in the UMC | None |
| Can you see who's in it, in the UMC? | Yes | No — the list lives in the identity system | Yes |
| When does it sync | Continuously, in the background — changes apply within minutes to about an hour | At each user's next login — which could be up to 30 days away | No sync — your changes apply immediately |
Not sure whether your organization has SCIM? You can't tell just by logging in — contact the uStudio Customer Success team (success@ustudio.com) and they'll confirm your configuration.
Option 1: Synced groups
Why choose this path: You want the member list to take care of itself. When someone joins the sales team, they see sales content; when they leave, it disappears — without anyone touching uStudio. This is the best option for large audiences or audiences that change often.
Your IT team identifies or creates a group in the identity system that matches your audience. These groups usually have automatic membership rules (for example, "everyone whose department is Sales"), so people are added and removed based on their employee record — no manual upkeep. IT then configures that group to be shared with uStudio.
What's required: Your IT team must have connected uStudio to your company's identity system. That connection comes in two flavors, and the flavor determines how your synced groups behave — mostly in when the sync happens.
Synced via SCIM
SCIM provisioning is a connection that continuously sends user and group information to uStudio. It works quietly in the background — you won't see any sign of it when you use the app.
Step 1 — Work with IT to define the group and have it sent to uStudio. Your IT team identifies or creates a group in the identity system that matches your audience. These groups usually have automatic membership rules (for example, "everyone whose department is Sales"), so people are added and removed based on their employee record — no manual upkeep. IT then configures the group to be sent to uStudio via the SCIM connection.
Step 2 — The group is automatically created for you. Once IT sends the group over the SCIM connection, it appears in the UMC automatically, ready for any uStudio admin to use when restricting content.
Good to know:
- Syncs continuously. Membership changes flow to uStudio automatically and take effect almost immediately — content appears in or disappears from a user's view as soon as they refresh a page in the app, even mid-session.
- You can see the member list in the UMC — useful for double-checking your audience before you publish. The list may look editable, but don't change it there: the identity system is the source of truth, and manual edits will be overwritten on the next sync.
Synced via SAML
If SCIM is not an option, you'll use SAML groups. Unlike SCIM, SAML doesn't sync in the background. Instead, each user's group membership syncs at the moment that user logs in. That has consequences for setup, timing, and visibility:
Step 1 — Work with IT to define the group and have it sent to uStudio. Your IT team identifies or creates a group in the identity system that matches your audience. These groups usually have automatic membership rules (for example, "everyone whose department is Sales"), so people are added and removed based on their employee record — no manual upkeep. IT then configures the group to be sent to uStudio via the SAML connection.
Step 2 — Create a corresponding group in the UMC and map it to the SAML group. Once mapped, it's available to any uStudio admin for restricting content.
Good to know:
- Changes wait for the next login. When someone is added to or removed from the group, their access updates the next time they log in — not immediately. Users typically stay logged in for a while (usually 30 days, but it depends on your organization's settings), so a removed user may keep seeing restricted content until their session expires. The same applies when defining new groups or adding users to existing groups. If you need access updated quickly, keep this in mind – you may need to instruct users to log out and log back in to apply the group updates.
- You can't see the member list in the UMC. Because membership arrives one user at a time, the authoritative list lives only in your identity system — if you need to verify who's in the group, ask your IT team.
Option 2: Manually managed groups in the UMC
Why choose this path: You know exactly who should be in the group, and it's a short list. There's no waiting on IT and nothing to configure — you build the group yourself in minutes. This is the right choice when your audience doesn't match anything the identity system tracks. This might be a pilot group, a cross-department committee, or uStudio admins previewing content before a mainstream release.
What's required: Nothing. Any uStudio admin can do this today by following this guide.
How it works: Create a group in the UMC and add members from the list of users uStudio knows about. Once created, the group is available to any uStudio admin for restricting content.
Good to know:
- Who can you add? Without SCIM, uStudio only knows about people who have logged in at least once — so a brand-new employee won't appear in the list until their first login. With SCIM, uStudio knows everyone who's been provisioned access, whether or not they've logged in yet.
- Changes apply immediately: add or remove someone, and their content updates as soon as they refresh a page in the app, even mid-session.
- The trade-off is upkeep. Nobody updates this list but uStudio admins — if a member changes roles or leaves the company, the group won't know until you edit it. That's why manual groups work best when they're small.


