IDP Support Center
  • Welcome
  • Getting started
    • What is IDP?
  • User Guide
    • User guide center
    • Get started with OXU
      • OXU Identity user guide
    • Account Management
      • Authentication
        • Sign up with Email and Password
        • Sign up with Google (optional)
        • Sign in with Email and Password
        • Google OIDC: Sign in to Google via OXU
        • Password requirements enforcement
        • Secure password hashing and storage
      • Account security
        • What should I do if I don't receive a verification code when signing up or forgot password?
        • Email verification
        • Two-Factor Authentication
          • Passkey authentication
          • 2FA-Email verification codes
          • MFA-Authenticator apps (TOTP)
          • MFA-Passkeys (FIDO2 / WebAuthn)
      • Data & Privacy
      • User Experience
        • Cross-platform web support
      • App Consent Management
    • Organization Admin App
      • Business Owner (Default Authority)
        • Organization Management
          • Organization creation
          • Domain ownership verification (DNS)
        • Organizational Structure
          • Organizational Units (OUs)
          • Workspaces
          • Hierarchical access scoping
        • Security & Governance
          • Enforced security policies
            • IP-Based access control
            • Geo-based access policies
            • Device and platform restrictions
          • Enforcing stronger authentication for risky login behavior
            • Risk Detection signals
            • Step-Up authentication
        • Roles & permissions
          • Assign role to user in Organization
          • Permissions list
      • SCIM – Automated user and workspace provisioning
        • What is SCIM used for?
        • User Lifecycle management
      • Administrator
        • Team & Access
          • Invite and manage users
          • Assign roles
          • Manage access at OU and Workspace level
            • Manage Access at Organizational Unit (OU)
            • Manage Workspace level
              • Team & Access – Members Management
        • Group management
        • Organization Unit
          • Create & manage Organization Units
          • Viewing and searching Organizational Units
          • Moving an Organizational Unit
          • Deleting an Organizational Unit
        • Manage activity logs of Organization's member
      • Become an OXU developer
      • App management - Workspace access
      • Report & Analytics Center
    • OXU Workspace
      • Guide to create workspace
      • Guide to manage workspace information
      • Guide to manage role and permissions
      • Applications
        • Guide to manage applications
        • OXU Developer
          • What is OXU developer
          • User guides
            • 1. Become OXU developer
            • 2. Create an app
            • 3. Input application info
              • About app ratings and reviews
            • 4. Config resource & security info
            • Security Best Practices
            • 5. Set up Pricing info
            • 6. Publish your app
              • Prepare before publishing your app
            • 7. Manage your app
              • App lifecycle
          • App versioning
        • OXU Store
          • What is OXU Store
          • 1. Register as an user
          • 2. Browsing & searching apps
          • 3. View app details
          • 4. Subscribe an app
            • Enable & Subscribe app for business workspace
          • 5. Manage subscriptions
          • 6. Rate & review an app
  • Support
    • Support center
      • What is Oten account & what can I do with Account Management App?
      • How to create account and password?
      • How to manage your Oten account information?
      • How to use MFA to protect your account?
      • What is WorkSpace & what can you do with WS?
      • What is Organization Admin app & what can you do with OAA?
    • Privacy Policy
    • Terms and conditions
      • Oten developer terms and conditions
      • Oten Store terms and conditions
    • FAQs
      • Store FAQs
      • Developer FAQ
    • Contact Us
  • Integration
    • Integration document
      • IDP integration
        • Environments: sandbox & production
        • Regular web application client
        • Native application client
        • Single page application client
        • SAML integration
        • Managing your integration applications
        • FAQ
      • What is SSO?
      • Why use SSO?
    • Provisioning connector
      • Google Workspace Configuration
    • Understand SSO flow
      • Overview
      • Flow Diagram
    • Developer Integration guide
      • Integration flow overview
    • Oten to OXU Migration guide
    • Prerequisites
      • Discovery Configuration
      • JAR Requirement - CRITICAL
      • JAR Complete Implementation Guide
      • PKCE Implementation Guide
        • Step 1: Choose OAuth Library
        • Step 2: Configure OAuth Client
        • Step 3: Implement Authorization Flow
        • Step 4: Handle Callback
        • Step 5: Token Management
      • Best practice
        • Security
      • Support & Troubleshoot
        • Common Errors
        • Debug and Troubleshooting
        • Contact Support
      • Appendix
        • Configuration Reference
        • Error Codes Reference
        • API Reference
        • Sample Code
        • Glossary
  • What's New
    • v1.0.29 - Aug 19, 2026
    • v1.0.28 - Aug 12, 2026
    • v1.0.27 - Aug 08, 2026
    • v1.0.26 - July 29 & 31, 2026
    • v1.0.25 - July 22, 2026
    • v1.0.24 - Jun 21, 2026
    • v1.0.23 - Jun 17, 2026
    • v1.0.22 - Jun 03, 2026
    • v1.0.21 - May 27, 2026
    • v1.0.20 - Apr 28, 2026
    • v1.0.19 - Apr 21, 2026
    • v1.0.18 - Apr 15, 2026
    • v1.0.17 - Apr 03, 2026
    • v1.0.16 - Mar 28, 2026
    • v1.0.15 - Mar 05 & 13, 2026
    • v1.0.14 - Feb 11, 2026
    • v1.0.13 - Jan 14, 2026
    • v1.0.12 - Jan 05, 2026
    • v1.0.11 - Jan 04, 2026
    • v1.0.10 - Dec 25, 2025
    • v1.0.9 - Dec 07, 2025
    • v1.0.8 - Nov 23, 2025
    • v1.0.7 - Nov 09, 2025
    • v1.0.6 - Oct 26, 2025
    • v1.0.5 - Sep 29, 2025
    • v1.0.4 - Sep 28, 2025
    • v1.0.3 - Sep 14, 2025
    • v1.0.2 - Aug 31, 2025
    • v1.0.1 - Aug 17, 2025
    • v1.0.0 - Aug 03, 2025
On this page
  1. User Guide
  2. Organization Admin App
  3. Business Owner (Default Authority)
  4. Organizational Structure

Hierarchical access scoping

PreviousWorkspacesNextSecurity & Governance

Last updated 6 months ago

  • Scope
  • I am new. Where should I start?
  • Purpose
  • Core Concepts
  • When should hierarchical access scoping be used?
  • Prerequisites
  • I already understand. How do I proceed step by step?
  • Policy Inheritance Rules
  • Common Examples

Scope

This document explains how hierarchical access scoping works within an organization using Organizational Units (Org Units).

Hierarchical access scoping defines where administrative authority and policy scope apply, based on the organization’s structural hierarchy.


I am new. Where should I start?

If you are new to hierarchical access scoping:

  • Think of the organization as a tree structure

  • Authority flows from parent Org Units to child Org Units

  • Administrators only manage the scope they are assigned to

This model helps large organizations control access without granting global permissions.


Purpose

Hierarchical access scoping enables organizations to:

  • Limit administrative actions to specific organizational areas

  • Apply security policies consistently through inheritance

  • Prevent over-privileged administrative access

  • Align system access with real-world organizational boundaries


The organization is structured as:

Organization (Root) → Org Unit (Parent) → Org Unit (Child) → Workspace

Each level represents a scope boundary.


Access scope defines:

  • Which users an administrator can manage

  • Which Org Units an administrator can view or modify

  • Where policies can be applied or overridden

Administrators cannot act outside their assigned scope.


Hierarchical access scoping is recommended when:

  • The organization has multiple departments or business units

  • Administrative responsibilities must be segmented

  • Different security policies apply to different groups

  • You want to avoid global admin privileges


Before using hierarchical access scoping:

  • Organizational Units must be defined

  • Administrative roles must support scoped permissions

  • Policy inheritance rules must be understood



  • Create Org Units that reflect your organization’s structure

  • Establish clear parent–child relationships

  • Keep the hierarchy as simple as possible


  • Assign administrators to a specific Org Unit

  • Define their role within that scope

  • Ensure they only see and manage resources within their assigned Org Unit and its children


  • Apply global policies at the root Org Unit

  • Apply more restrictive policies at child Org Units if needed

  • Allow policy inheritance unless explicitly overridden


Administrators can:

  • View and manage users within their Org Unit scope

  • Assign users to child Org Units

  • Enforce policies relevant to their scope

They cannot manage users outside their scope.


  • Test admin access at each Org Unit level

  • Verify visibility and permissions

  • Confirm that cross-scope access is blocked


  • Policies applied at a parent Org Unit are inherited by child Org Units

  • Child Org Units may override certain policies if allowed

  • Overrides never affect parent Org Units


  • Org Unit: Engineering

  • Admin Scope: Engineering

  • Access: Engineering + all sub-teams

  • No access to Finance or HR


  • Org Unit: APAC

  • Policy: Geo-based access restriction

  • Scope: Applies only to APAC users

Core Concepts

Organizational Hierarchy

Access Scope

When should hierarchical access scoping be used?

Prerequisites

I already understand. How do I proceed step by step?

1. Define the Organizational Hierarchy

2. Assign Administrative Scope

3. Apply Policies at the Appropriate Level

4. Manage Users Within Scope

5. Validate Scope Enforcement

Policy Inheritance Rules

Common Examples

Example 1: Department-Level Administration

Example 2: Regional Policy Control