Access Control Groups
Access Control Groups (ACGs) are used to restrict the user privileges that a REDCap user can be granted in a project. ACGs do not define the privileges a user will have in a given project; rather, they define the set of allowable rights that the user is able to be granted. ACGs are defined at the system level, and when the ACG feature is enabled, it will be implemented on all projects in the system, specifically when a user is being added to a project or when their user privileges are being modified in a project. Using ACGs is completely optional, and the feature can be enabled or disabled at any point. For existing projects that already have users, there is an ACG Compliance page in every project to allow admins to determine if existing users have non-compliant ACG rights, and if so, provides tools to notify User Rights managers regarding users with non-compliant rights or to easily expire users.