Published at: 2026-09-17
Configure address book isolation
Configure Directory Isolation rules to control member visibility between departments and user groups in the Org Structure.
Overview
💡 Enable address book isolation to hide selected departments or user groups from people selectors and the address book tree. Use this capability to isolate sensitive business lines, outsourced teams, or subsidiaries and protect enterprise information and employee privacy.
Before you begin
[!IMPORTANT] - Role permissions: System Administrators have full configuration permissions.
Procedure
1. Enable isolation and global settings
- Go to Setup > Organization Structure > Directory Isolation.
- Turn on Directory Isolation.
- Configure rules for employees without a department and super employees:
- Employees without a department:
- Select Hide employees without a department to remove them from the public address book.
- Select Employees without a department can view only themselves to prevent them from viewing external colleagues.
- Select Do not receive company-wide Feeds to block company-wide broadcasts.
- Super employee whitelist: In Super Employees Allowed to View All Address Books, add executives, HR staff, or other employees who need global visibility. Super employees are not affected by isolation settings. ### 2. Configure isolated department rules
- Employees without a department:
- Open the Isolated Departments tab and click Add.
- Select the target department.
- Configure the department isolation details:
- Hide in address book:
- Do not hide
- Hide outside the department except the Parent Department manager
- Hide outside the department: Add a Whitelist to allow selected departments to view the isolated department.
- Restrict address book access:
- No restriction
- View only within the department
- View only themselves: Configure a View Whitelist to allow members to view selected departments.
- Receive Feeds, such as mentions, Cc messages, and receipts:
- Receive messages sent to the parent and current departments
- Receive only messages sent to the current department
- Hide in address book:
- Click Save.
3. Configure isolated user group rules
For temporary teams or virtual groups that cross administrative departments, configure isolation by user group:
- Open the Isolated User Groups tab and click Add.
- Select a user group and choose its visibility rule:
- Do not hide: Everyone can view the group.
- Hide by default: Only group members can view the group.
- Show to whitelist members and hide from blacklist members: Add members to a whitelist or blacklist.
- Click Save.
Verify the result
- Create an Outsourced Development Team department and set it to Hide outside the department.
- Sign in with a super employee account. Confirm that you can search for and view the Outsourced Development Team and its employees.
- Sign in with a regular sales account that is not on the whitelist. Search for an Outsourced Development Team employee in a people selector and confirm that no matching result appears.