Skip to main content

Projects

Projects organize your Connect organization into a tree. Every account, Group, Boundary, change request, and Decommission action belongs to one project, and roles are granted per project, so projects are how you divide Connect between teams. Managing projects needs the Administrators or Project Managers role.

What projects control

  • It holds accounts. An account is created in a project, and the inventory it discovers belongs to that project. The Sources column on the Projects page counts the accounts in each project and the projects beneath it.
  • It holds the things you build. Groups, Boundaries, change requests, and Decommission actions each pick a project when they're created. For Groups and actions the choice is permanent.
  • It scopes roles. A role granted on a project applies to it and to every project beneath it. See Role scope and projects.
  • It's a filter. Inventory and Decommission can be filtered by project, and a Group's Project criterion selects members by the project their account is in.

The root of the tree is your organization itself. Objects created there are visible to anyone whose roles cover the root.

Choosing a project structure

A single project, the root, is fine when one team runs everything. Create sub-projects when you need:

  • Separate ownership. A business unit or region manages its own accounts and Groups, and sees only those.
  • Limited access for requesters. Firewall Change Requestors granted on a sub-project can only create requests in it, and the inventory and Group pickers offer only that project's items.

Keep the tree shallow. Every level is one more place to check when someone is missing access.

Creating and editing projects

Settings > Projects lists projects as paths, so a nested project shows its parents. Click New Project and enter a Name, an optional Description, and the Parent. The parent is set when the project is created; the name and description can be edited afterwards.

A project can be deleted once it, and every project beneath it, holds no accounts or sub-projects; while accounts remain, the delete button is disabled and says so. An account stays in the project it was created in, so to remove a project, first delete its accounts or re-create them in another project.