Hierarchical RBAC

Roles and permissions that follow your real org structure.

Hierarchical RBAC across a 5-level org tree. Scope permissions to any level — division, department, team — with automatic inheritance and full audit. Works on top of your existing IdP.

5-level organization hierarchy

Model divisions, departments, teams, and projects. Roles assigned at any level inherit downward automatically.

L0
TenantTop-level isolation per customer
L1
DivisionBusiness units or regions
L2
DepartmentFunctional groups within a division
L3
TeamWorking groups within a department
L4
ProjectScoped workstreams or engagements

Beyond flat roles

5-level org tree

Model your real organization — tenant, division, department, team, project. Roles and permissions inherit down the tree automatically.

Org-scoped resources

Bind applications, feature flags, accounts, and API keys to an organization. Only users with access to that part of the tree can see or manage them.

Scoped role assignments

Assign a user the "Editor" role in one department and "Viewer" in another. Same user, different permissions per org node — no duplication.

Role inheritance

Roles assigned at a parent org flow down to every child org automatically. No manual propagation.

Least-privilege by default

Users start with no permissions. Every grant is explicit, scoped to an org level, and time-boundable with temporary grants that auto-expire.

Full audit trail

Every role assignment and access decision is logged. See who has access to what at any point in time — across every org level.

Frequently asked questions

What is hierarchical RBAC?

Hierarchical RBAC (HRBAC) extends traditional role-based access control by organizing roles and permissions within a tree structure that mirrors your real org chart. Instead of flat, global roles, permissions are scoped to specific levels — a user can be an Admin in one department and a Viewer in another.

How is this different from flat RBAC in Okta or Auth0?

Okta and Auth0 provide flat role lists — a user either has a role or doesn't. AccessIQ adds org-scoped assignments (Editor in Marketing, Viewer in Engineering) and multi-level inheritance on top. Your IdP still handles authentication; AccessIQ handles the authorization your IdP doesn't.

How deep can the org hierarchy go?

Up to 5 levels: tenant, division, department, team, and project. Each level supports its own role assignments, with automatic inheritance from parent to child nodes.

Permissions that match your org chart

Start free, or book a walkthrough and we’ll map your current roles to AccessIQ’s hierarchy.