Deep Dive: Domain Groups and permissions — what are they all about?

Here's a screenshot of Domain Group settings:

Expensify Card unapproved expense limit
Strictly enforce expense policy rules
If enabled, every rule that has been set for the policy will need to be satisfied before the report can be submitted for approval. If there is a policy violation on an expense, the employee will not be able to submit the report. If this feature is disabled, employees will be able to dismiss policy violation notifications and submit their reports without correcting them.
Restrict primary login selection
If enabled, users will not be able to make a non-company domain email address their primary email address (thus bypassing permissions set up via Domain Control). Employees will still be allowed to add secondary logins.
Restrict expense policy creation/removal
If enabled, users will be prevented from creating new group policies or personal subscriptions, and will not be able to remove themselves from an existing policy.
Note: If enabling this rule, it is recommended that a separate group is created for admins who need the ability to create new reports with the rule disabled.
Restrict primary policy selection
If enabled, group members will only be able to create and submit reports under the designated policy. This is useful when you have employees that are approvers for multiple policies but should only submit their own expenses under a single policy.
Have a question or want to know more? Start a discussion here!