System groups
A system group is a group of users (subjects) to which you can assign roles. In Yandex Cloud, there are three types of system groups: All users in organization X, All users in federation N, and All users in userpool P. These groups allow you to grant access to your resources for a specific user group, but only for the operations that are allowed by the assigned role. System groups do not include service accounts.
System groups are dynamic: any new user added to an organization, federation, or pool automatically inherits all the permissions assigned to that organization, federation, or pool. When a user is removed from an organization, federation, or pool, such permissions are automatically revoked.
It is unsafe to assign roles with extensive permissions, such as editor or admin, to system groups.
All users in organization X
All users in organization X includes all organization X users.
All users in federation N
All users in federation N includes all identity federation N users.
All users in userpool P
All users in userpool P includes all local users of the P user pool the group belongs to.