Security
Configuring 3-tier scope RBAC
0views0comments
Setting up global/tenant/site roles and the delegate/self-assign mechanism.
Overview
SITESAFF RBAC has three scope tiers: global, tenant (organization), and site — enabling fine-grained, context-aware permissions.
Assigning permissions
Each role links to permissions through a join table with two flags, can_delegate and can_self_assign, controlling who can hand off access to whom.
Enforcement
Permissions are auto-initialized from router metadata; non-super-admins can only grant permissions they themselves were delegated.
Tags
rbacsecurity
Docs
← BackCategory
Security · Docs