RBAC
Assign roles to users and let roles carry permissions. The workhorse of SaaS authorization.
- Predefined role templates
- Tenant-scoped roles
- Role hierarchy inheritance
Authorization
Enforce least-privilege access with groups, roles, and fine-grained permissions, from a single app to multi-tenant estates, without rewriting your auth stack.
Flexible models
Start with simple roles and evolve to attribute- and relationship-based policies as your product grows. No migration required.
Assign roles to users and let roles carry permissions. The workhorse of SaaS authorization.
Model teams the way your customers do, then attach permissions to the group instead of to each user.
Evaluate user attributes, resource properties, and context to make dynamic access decisions.
Model complex hierarchies like organizations, workspaces, and projects, with permissions that inherit naturally.
Define roles, groups, and permissions per tenant and environment.
Check access with one SDK call before sensitive actions run.
Review every allow and deny decision from a single trail.
Open the console to model groups, attach permissions, and align policy with how your teams ship.