# Groups > [!WARNING] > This is a design document and does not necessarily reflect the current state > of the implementation. WIP: A group is only valid on a single domain, except for global service groups (eg. `admins`). A group has permissions to perform some actions on a domain.