Nested groups: process rights not carried over

Nested groups: process rights not carried over

This article was created in response to a support issue logged with K2. The content may include typographical errors and may be revised at any time without notice. This article is not considered official documentation for K2 software and is provided "as is" with no warranties.
This article has been archived, and/or refers to legacy products, components or features. The content in this article is offered "as is" and will no longer be updated. Archived content is provided for reference purposes only. This content does not infer that the product, component or feature is supported, or that the product, component or feature will continue to function as described herein.


Certain users belonging in nested groups are not able to trigger Workflows, despite being granted start rights.


Some users belonging in nested groups don't have their process rights carried over:


"UserA" who is a member of "SubGroupA," is not able to start a process instance.
"SubGroupA" is a member of "MainGroup".
"MainGroup" has been granted with process start rights.

Troubleshooting Steps

  1. Enable the Resolve Nested Group property from either K2 Workspace or K2 Management.

    On K2 Workspace:

    On the K2 Management site:

  2. Restart the K2 Blackpearl service.

  3. Run the script to expire the group:

    UPDATE [K2].[Identity].[Identity]
    SET [ExpireOn] = GETDATE(),
    [Resolved] = 0,
    [ContainerResolved] = 0,
    [ContainersExpireOn] = GETDATE(),
    [MembersResolved] = 0,
    [MembersExpireOn] = GETDATE()
    WHERE FQN = 'K2:DENALLIX\MainGroup'

  4. Run the UMUser Get Group Users SmartObject method from the SmartObject Service Tester and provide the name of the AD Group and the security label.
Labels: (1)
Version history
Revision #:
1 of 1
Last update:
‎09-11-2017 06:23 PM
Updated by: