Hierarchical RBAC

Roles and permissions that follow your real org structure.

Hierarchical RBAC + ABAC across a 5-level org tree. Scope permissions to any level — division, department, team — with automatic inheritance and full audit. Works on top of your existing IdP.

5-level organization hierarchy

Model divisions, departments, teams, and projects. Roles assigned at any level inherit downward automatically.

L0
TenantTop-level isolation per customer
L1
DivisionBusiness units or regions
L2
DepartmentFunctional groups within a division
L3
TeamWorking groups within a department
L4
ProjectScoped workstreams or engagements

Beyond flat roles

5-level org tree

Model your real organization — tenant, division, department, team, project. Roles and permissions inherit down the tree automatically.

RBAC + ABAC combined

Start with role-based policies, then layer attribute-based conditions — time windows, IP ranges, risk scores, custom attributes — for fine-grained control.

Scoped role assignments

Assign a user the "Editor" role in one department and "Viewer" in another. Same user, different permissions per org node — no duplication.

Policy inheritance

Policies set at a parent org flow down to every child. Override at any level when exceptions are needed. No manual propagation.

Least-privilege by default

Users start with no permissions. Every grant is explicit, scoped to an org level, and time-boundable with temporary grants that auto-expire.

Full audit trail

Every role assignment, policy change, and access decision is logged. See who has access to what at any point in time — across every org level.

Frequently asked questions

What is hierarchical RBAC?

Hierarchical RBAC (HRBAC) extends traditional role-based access control by organizing roles and permissions within a tree structure that mirrors your real org chart. Instead of flat, global roles, permissions are scoped to specific levels — a user can be an Admin in one department and a Viewer in another.

How is this different from flat RBAC in Okta or Auth0?

Okta and Auth0 provide flat role lists — a user either has a role or doesn't. AccessIQ adds org-scoped assignments (Editor in Marketing, Viewer in Engineering), multi-level inheritance, and attribute-based conditions on top. Your IdP still handles authentication; AccessIQ handles the authorization your IdP doesn't.

Can I combine RBAC with attribute-based policies?

Yes. AccessIQ supports hybrid RBAC + ABAC. Define roles for broad access patterns, then add ABAC conditions — time windows, IP ranges, risk scores, department attributes — for fine-grained decisions. Policies compose, so you don't have to choose one model over the other.

How deep can the org hierarchy go?

Up to 5 levels: tenant, division, department, team, and project. Each level supports its own role assignments and policy overrides, with automatic inheritance from parent to child nodes.

Permissions that match your org chart

Start free, or book a walkthrough and we’ll map your current roles to AccessIQ’s hierarchy.