The pain
- The number of roles grows as tenants and teams multiply.
- One role set cannot answer same-group vs other-group access cleanly.
- Spreadsheets hide the pattern: who can see a customer record, who can edit it, and who must be blocked.
Use case
Many multi-tenant products hit the same problem: each new tenant, team, or customer segment creates yet another role. The result is a model that is hard to reason about and harder to approve.
In multi-tenant SaaS, the important question is not simply “what role does this user have?” It is “what tenant, what group, and what relationship does this user have to the record?” That is where same-group vs other-group access, ownership, and field sensitivity become visible.