For Admins and IT Admins. Only users with the Admin or IT Admin role can create and manage user groups.
Overview
A user group is a named set of monitored users. Groups serve three purposes in MCO eComms:
Organizational structure — Groups can reflect your company's departments, regions, or legal entities.
Supervision purview — Groups define which messages and alerts each supervisor can access.
Policy targeting — Groups determine which detection policies apply to which users.
The same user can belong to multiple groups. Groups are flat — they cannot be nested inside one another. MCO eComms supports one level of group structure only.
Managing user groups
Groups are managed from Settings > User Groups. The Groups list shows each group's name, current members, and the policy modules attached to it.
To create a group, click Create new group. To edit an existing group, click the edit icon at the right end of the group's row.
Group properties reference
Property | Description |
Group name | A unique display name for the group. |
Supervisors | One or more users with the Supervisor role assigned to oversee this group's messages and alerts. |
Review Monitoring | Whether message archive review is active for this group. Can be set to On, Off, or Same as Account (inherits the account-level default). |
Retention Policy | How long captured messages are retained before deletion. Can be set to a specific period or Same as Account. |
Legal Hold | When enabled, messages for users in this group are preserved regardless of the retention period. |
Policy Modules | The detection policies applied to users in this group. Policy modules are configured separately and attached to groups from the Policy Module settings. |
Supervisors and the supervision purview
When you assign one or more supervisors to a user group, those supervisors can only see messages and alerts for users who belong to groups in their purview. Supervisors have no visibility into messages or alerts for users outside their assigned groups.
Supervision purviews can overlap — the same user can belong to multiple groups, and multiple supervisors can be assigned to the same group. This allows flexible coverage models such as:
A primary supervisor and a backup who both monitor the same team.
A regional supervisor who covers one group and a global compliance supervisor who covers all groups.
Design your groups to reflect the actual oversight responsibilities in your organization. A supervisor who cannot see a user's messages cannot review that user's alerts.
Policy modules and alert generation
Detection policies are attached to groups as policy modules. When a monitored communication involves a participant who belongs to a group, MCO eComms evaluates that communication against the policy modules assigned to the group.
If the communication triggers a policy, an alert is created. Alerts are generated separately for each group whose policies were triggered and whose members participated in the communication. This means a single message can produce multiple alerts — one per group — if multiple groups with different policies are involved.
Each alert is routed to the supervisors of the group whose policy was triggered. Supervisors see only the alerts within their purview.
Account-wide policies
You can apply a policy module to all monitored users regardless of their group membership. This is configured on the Policy Module details page using the Apply for everyone option.
Use Apply for everyone for baseline detection logic that must cover all users — for example, a prohibition on sharing material non-public information. Use group-specific policies for detection logic that applies only to a subset of your workforce.
Design considerations
Getting the group structure right is essential for accurate alert routing, complete message coverage, and manageable supervisor workloads. Consider the following before finalizing your groups:
Keep groups aligned with real oversight boundaries. A group is only useful if a named supervisor is responsible for the users in it. Avoid creating groups that no supervisor monitors.
Use overlap deliberately. A user in multiple groups receives alerts from all policies attached to those groups. Overlap increases coverage but also increases alert volume for supervisors.
Account-wide policies complement group policies — they do not replace them. Apply account-wide policies for rules that must apply universally, and use group-specific policies for targeted or segment-specific detection.
Groups are not a nested hierarchy. If your organization has sub-teams within departments, you must represent these as separate flat groups. Consider how supervisors will be assigned across those groups.
