Teams
Choose which organization teams can use each managed Nexus machine
Teams controls which Msty Account teams can reach each managed Msty Nexus machine. People and organization roles remain managed in Msty Account; Nexus manages machine access assignments.
Who can manage access
Organization owners and administrators can change team-to-machine access. Other members can view only the information their role permits.
If the organization selector is present, confirm the correct organization before making changes.
Assign machine access
- Open Teams.
- Select the organization.
- Choose a team.
- Enable the managed machines that team should be able to reach.
- Remove access from machines the team no longer needs.
Changes affect Nexus access; they do not change a person's Msty Account role or membership.
Relationship to Fleet
Fleet manages machines, connectivity, endpoints, and machine-level operations. Teams manages who may reach those machines.
A machine can exist in Fleet without a team assignment. If managed Guard policy is enabled, every governed machine needs exactly one team assignment so the control plane can issue the correct policy.
Managed Guard
Enterprise organizations can publish organization Guard policy by team. The control plane reduces and signs the relevant policy for each assigned machine, and the Runtime verifies and enforces it locally.
If a governed machine has no team, several teams, or no current team policy, policy synchronization cannot choose a valid result. Resolve the assignment rather than bypassing the entitlement or policy check.
Security boundary
Team assignment does not share provider credentials or client-token plaintext. It grants managed access according to the organization's Nexus entitlement and policy.
Review Security before granting access to machines with network or hosted endpoints enabled.