The group owner is assigned by the application owner or any admin with the appropriate permissions. They are entitled to manage user access within the group by:
- Adding or removing members from the group.
- Adding or removing application roles from the group.
Group owner can create attributes at both group level and for the user associated with it, modify general and contact information, but cannot create roles or groups. They can assign another group owner and often have multiple owners to manage the group if the primary owner is unavailable or unable to perform their duties. Members can be promoted to owner status or demoted back to member status.