RBAC design tool

RBAC design that isn't a spreadsheet

Model who can access what by role, by relationship, and by field-level exception, as a permission hierarchy your whole team can actually read. Get sign-off, then present it live in grooming calls.

Starter is free forever. Pro is $10 once, no subscription.

Permisly PRESENTER
Approved
Manager · Record
Own record
ViewCreateEditDelete
Same group
ViewEditDelete
* Only while record status is “Open”
Other group
ViewEditDelete
* Read-only, sensitive fields hidden
Superior’s record
ViewEditDelete
In plain language. A Manager fully manages their own deals. In their group they can edit only while the deal is Open. Other groups are view-only with sensitive fields hidden. They cannot see a superior’s record.
Built for the people who have to explain access out loud.
Product ownersSecurity / GRCEng leadsImplementation partners
The problem

The spreadsheet breaks the moment access depends on relationship, not just role

A flat grid answers “can Editor view?” It can't answer “can a Manager view a record created by their own Staff, but not one from another group, and only if sensitive fields are hidden?” That's not a formatting problem. It's a dimensionality problem. Permisly models the fourth dimension a spreadsheet can't: the relationship between the actor and the record, which is exactly what relationship-based access control is built on.

Spreadsheet

Every cell collapses to the same “View”.

RoleViewEditDelete
AdminYYY
ManagerYYN
StaffYownN

No relationship. No field exception. No condition. The interesting cases get buried in a comment column nobody reads on the call.

Permisly

The same actor, scoped by relationship.

ScopeViewEditDelete
Own recordFullFullFull
Same groupFullIf Open
Other groupRedacted

Relationship is a first-class axis. Conditions and field hiding sit next to the permission, not in a footnote three tabs over.

How it works

Three steps, not a slide deck

Design the RBAC model once. Send it for sign-off. Read it aloud on the grooming call without translating a permission matrix in your head.

01

Build the hierarchy

Roles, resources, actions, and relationship scopes, yours rather than a template that almost fits.

Role · ManagerResource · DealsAction · EditScope · Same group
02

Get it approved

Send a link. Your lead reviews, edits if needed, approves. You see exactly what changed.

Send link → Review → Approve → Signed off
03

Present it live

Presenter mode steps through one role at a time, in plain language, built to be read aloud on a call.

Team Lead / DealsView · FullEdit · Conditional
Features

Built for how POs actually work

The fourth dimension

Relationship-scoped permissions

Access is not only role × action. It is role × action × relationship to the record, with own, same group, other group, and superior scopes, plus field-level exceptions attached to each scope.

Own recordView Create Edit Delete
Same groupEdit if Open
Other groupView, sensitive fields hidden

Inheritance with override

Set default permissions once at the parent role and override only where it differs.

Custom permission levels & colors

Define workspace-specific permission states beyond a generic 3-state grid.

CSV import

Import your existing access spreadsheet instantly instead of starting from scratch.

Read-only share links

Zero-login viewer links so your whole team can follow along live on grooming calls.

Presenter mode

Read the model out loud. Don’t decode it.

One role at a time. Plain language. Built for the fifteen minutes on a grooming call when everyone is staring at you and the spreadsheet is already lying.

What you say on the call
“A Manager can fully manage their own deals. On deals in their group they can edit only while the record is Open. On everyone else’s deals they can view, but salary and notes are hidden. They cannot see a superior’s record at all.”
Pricing

Free to build. $10 once to share it.

No seat math. No annual dance. Design locally for free. Pay once when the team needs to sign off and follow along.

Free

$0 forever

Everything you need to design the hierarchy on your own machine.

  • 1 workspace
  • Full hierarchy, matrix, and inheritance builder
  • Presenter mode
Start free, no card

Permisly Pro

$10 one-time

Unlock team sign-off, viewer links, and as many workspaces as the work needs.

  • Unlimited workspaces
  • Approval workflow
  • Read-only share links
  • No subscription. Pay once and keep it
Get Permisly Pro

FAQ

Questions

No. Permisly is a design and requirements tool for the access model itself, used before or alongside implementation. It doesn't enforce permissions in a live system.

Start with one hierarchy

Stop presenting a spreadsheet on your next grooming call

No card for Starter. Open a workspace, import a CSV, or start from the Deals example on this page.

Start free, no card