The groups Command Explained

The groups Command Explained

groups answers a simple but foundational question: which groups does this user actually belong to? Groups are the mechanism Linux uses to grant the same access to multiple users at once, without needing to set individual permissions for every single person who needs access to a shared resource.

Basic usage

groups
# colton sudo docker developers

groups alice
# alice : alice developers

Run with no argument, groups shows the groups for whoever is currently logged in. Given a username, it shows that specific user’s group memberships instead.

Primary group vs supplementary groups

id colton
# uid=1000(colton) gid=1000(colton) groups=1000(colton),27(sudo),999(docker),1001(developers)

Every user has exactly one primary group (gid=1000(colton) in the output above), which becomes the owning group automatically assigned to any new file that user creates. A user can additionally belong to any number of supplementary groups (sudo, docker, developers here), which grant access to whatever those groups own without affecting what group new files get created under.

touch newfile.txt
ls -l newfile.txt
# -rw-r--r-- 1 colton colton ... newfile.txt
#                        └┬───┘
#                    primary group, NOT one of the
#                    supplementary groups, is used here

Where group data actually lives: /etc/group

cat /etc/group
# sudo:x:27:colton
# docker:x:999:colton,alice
# developers:x:1001:colton,bob

grep developers /etc/group
# developers:x:1001:colton,bob

/etc/group lists every group’s name, its numeric GID, and a comma-separated list of usernames belonging to it as a supplementary member. A user’s primary group is recorded separately, in /etc/passwd, as a GID number rather than appearing in this member list at all.

grep colton /etc/passwd
# colton:x:1000:1000:Colton:/home/colton:/bin/bash
#              └┬─┘
#          primary group GID (1000, matching colton's own group)

Adding a user to a group: the -aG pattern

sudo usermod -aG docker colton

-a (append) and -G (supplementary groups) together add a user to a group without disturbing their existing memberships. This specific combination is important enough to call out directly, because the alternative is a genuinely dangerous mistake:

# DANGEROUS: omitting -a
sudo usermod -G docker colton
# this REPLACES colton's entire supplementary group list with
# ONLY docker, silently removing them from sudo, developers,
# and every other group they previously belonged to

Always use -aG together, never -G alone, unless you genuinely intend to wipe out and replace a user’s entire supplementary group membership in one step.

Why a new group membership does not show up immediately

sudo usermod -aG docker colton
groups
# colton sudo developers
# (docker is missing! even though the command above succeeded)

Group membership is loaded into a session when it starts, generally at login, and is not automatically refreshed for shells that are already running. The fix is one of:

# Option 1: log out and log back in completely

# Option 2: start a fresh login shell as the same user
su - colton

# Option 3: temporarily switch primary group for this session only
newgrp docker
groups
# docker colton sudo developers

newgrp is the fastest way to confirm a new group membership actually works without needing a full logout, since it forces the current shell to pick up fresh group information immediately.

Group management commands beyond groups itself

# Create a new group
sudo groupadd designers

# Remove a group
sudo groupdel designers

# Rename an existing group
sudo groupmod -n newname oldname

# Change a user's primary group
sudo usermod -g newprimarygroup username

groups itself is read-only, purely for checking membership. Actually creating groups, deleting them, or changing a user’s membership requires the separate usermod, groupadd, groupdel, and groupmod commands, all of which require root privileges since they affect system-wide account configuration.

Frequently Asked Questions

What does the groups command do?

groups prints the list of groups a given user belongs to. Run with no argument, it shows the groups for your currently logged-in user. Run with a username as an argument, such as groups alice, it shows the groups that specific user belongs to instead.

What is the difference between a primary group and a supplementary group?

Every user has exactly one primary group, which becomes the owning group for any new file that user creates by default. A user can additionally belong to any number of supplementary (or secondary) groups, which grant access to files and directories owned by those groups without changing what group new files get created with. groups lists all of them together, with the primary group typically shown first.

Where is group membership actually stored on the system?

/etc/group stores every group’s name, numeric GID, and its list of member usernames as a supplementary group. A user’s primary group is instead recorded in /etc/passwd, as a GID field alongside their other account details, rather than in /etc/group’s member list.

How do I add a user to a group?

Use usermod -aG groupname username, where -a means append (add to the existing list without removing current memberships) and -G specifies the group to add. Omitting -a and using just -G alone is a common and dangerous mistake, since plain -G REPLACES a user’s entire supplementary group list with only the group specified, silently removing them from every other group they previously belonged to.

Why doesn’t a new group membership take effect immediately in my current terminal?

Group membership is read and cached when a session starts, typically at login. Adding a user to a new group with usermod does not retroactively update any shell sessions already running under that user; you need to log out and back in, or start a fresh session with newgrp groupname or su - username, for the change to actually take effect in that terminal.

What is the newgrp command used for?

newgrp temporarily switches your primary group for the duration of the current shell session, without requiring a full logout and login. It is most commonly used to immediately test whether a newly added group membership works correctly, since it forces the shell to reload group membership information right away rather than waiting for the next full login.