1. Platform
  2. Use Cases
  3. Enterprise Hierarchy
Use Case Enterprise Hierarchy

Model your org exactly as it's structured

Flat RBAC can't model regions, divisions, departments, and teams. Canopy scopes permissions to exactly where they apply: a regional manager sees their region, a team lead sees their team, and a global admin sees everything.

Any structure Scoped at every level Visual builder
Organization structure Region Office Team
Acme GlobalRootWest RegionRegionEast RegionRegionSF OfficeOfficeLA OfficeOfficeNY OfficeOfficeBOS OfficeOfficeSalesOpsSalesEngSalesCSEngOps
Model any structure

Your schema, enforced by Canopy

Define node types (region, office, department, team) and the parent-child rules between them. Canopy enforces your schema: you can't accidentally put a team under a team if your schema doesn't allow it.

Define your own node types
Set parent-child rules between them
Invalid structures are rejected automatically
schema · node types & rules
Region Office Department Team
Region Office Team Allowed
Office Department Team Allowed
Team Team Rejected
Scoped visibility

Everyone sees their slice, and only theirs

Users see only the parts of the hierarchy they have access to. A regional manager sees their region and everything below it, but nothing outside. This isn't filtering: it's enforced at the API level.

Regional Manager
Scoped to West
HQ
West
East
SF
LA
Sees West + below
Team Lead
Scoped to Sales
HQ
West
East
Sales
Ops
Sees only Sales
Global Admin
Scoped to Root
HQ
West
East
SF
LA
NY
BOS
Sees everything
Assignment scheduling

Access that starts and ends on schedule

Grant temporary access with effective_from and effective_to dates. Contractor access that auto-expires, planned promotions that activate on a future date, with no manual cleanup.

Now · Jun 26
Jun 1 Jun 26 Jul 15 Aug 15 Sep 1
Regional Manager · West
active · permanent
Contractor · LA Office
expires Jul 15
Promotion · VP East
activates Jul 15
Active now
Scheduled effective_from
Auto-expiring effective_to
Visual hierarchy builder

Build your tree without writing code

Build and manage your organizational tree through the Developer Console. Create nodes, drag to reorder, and assign identities. Operators can manage the full structure without engineering involvement.

+Add node Assign Schema − 100% +
Acme GlobalRootWest RegionRegionEast RegionRegionSF OfficeOfficeLA OfficeOffice+Add child…

Ready to simplify access control?

Create an account and have authentication and hierarchical access control running today.