Hierarchical access scoping
Last updated
Last updated
This document explains how hierarchical access scoping works within an organization using Organizational Units (Org Units).
Hierarchical access scoping defines where administrative authority and policy scope apply, based on the organization’s structural hierarchy.
If you are new to hierarchical access scoping:
Think of the organization as a tree structure
Authority flows from parent Org Units to child Org Units
Administrators only manage the scope they are assigned to
This model helps large organizations control access without granting global permissions.
Hierarchical access scoping enables organizations to:
Limit administrative actions to specific organizational areas
Apply security policies consistently through inheritance
Prevent over-privileged administrative access
Align system access with real-world organizational boundaries
The organization is structured as:
Organization (Root) → Org Unit (Parent) → Org Unit (Child) → Workspace
Each level represents a scope boundary.
Access scope defines:
Administrators cannot act outside their assigned scope.
Hierarchical access scoping is recommended when:
Before using hierarchical access scoping:
Administrators can:
They cannot manage users outside their scope.
Which users an administrator can manage
Which Org Units an administrator can view or modify
Where policies can be applied or overridden
The organization has multiple departments or business units
Administrative responsibilities must be segmented
Different security policies apply to different groups
You want to avoid global admin privileges
Organizational Units must be defined
Administrative roles must support scoped permissions
Policy inheritance rules must be understood
Create Org Units that reflect your organization’s structure
Establish clear parent–child relationships
Keep the hierarchy as simple as possible
Assign administrators to a specific Org Unit
Define their role within that scope
Ensure they only see and manage resources within their assigned Org Unit and its children
Apply global policies at the root Org Unit
Apply more restrictive policies at child Org Units if needed
Allow policy inheritance unless explicitly overridden
View and manage users within their Org Unit scope
Assign users to child Org Units
Enforce policies relevant to their scope
Test admin access at each Org Unit level
Verify visibility and permissions
Confirm that cross-scope access is blocked
Policies applied at a parent Org Unit are inherited by child Org Units
Child Org Units may override certain policies if allowed
Overrides never affect parent Org Units
Org Unit: Engineering
Admin Scope: Engineering
Access: Engineering + all sub-teams
No access to Finance or HR
Org Unit: APAC
Policy: Geo-based access restriction
Scope: Applies only to APAC users