As soon as you need regions, departments, or teams, flat roles stop working: permissions don't cascade, access becomes manual, and every new node means more assignments. Canopy solves this with hierarchical RBAC: roles assigned at a parent node automatically apply to all descendants.
Every environment starts as flat RBAC with a single root node and environment-wide roles. When your customers grow, add regions, departments, or teams. Existing assignments cascade automatically. No migrations, no data rewrites, no code changes.
A single root node with environment-wide roles. Simple by default.
Add regions and teams. Existing roles cascade into the new structure instantly.
Need to simplify again? Revert to flat at any time. Canopy consolidates assignments automatically.
The same org, modeled two ways. One scales with every new location; the other breaks.
Regional managers need access to all offices in their region. Store managers need one location. Department leads need specific teams. Here's what that takes in each model.
Assign a role at any node and permissions cascade to every descendant. A regional manager assigned at West Region automatically has access to every office, team, and project underneath, without a single duplicate assignment.
Offices, teams, and projects beneath the node inherit instantly.
Add an office under a region and it adopts the regional manager's permissions. Zero configuration.
Ask Canopy whether an identity has a permission at a node, and get an instant answer. Evaluation considers direct assignments, inherited roles, and the full hierarchy path.
The full path from root to node is evaluated in a single pass.
No client-side merging. The same inputs always return the same answer.
The same five questions, answered by each model.
| Flat RBAC | Hierarchical (Canopy) | |
|---|---|---|
| Role scope | Org-wide | Any node in the tree |
| Inheritance | None | Permissions cascade downward |
| New nodes | Manual re-assignment | Automatic propagation |
| Visibility | All or nothing | Scoped to assignment point |
| Structure | Breaks with growth | Designed for it |
Build and manage your hierarchy through the Developer Console. Drag nodes to reorder, assign identities at any level, and see inherited access at a glance.