4 ms·
Ask HN: How to best design a hierarchy of user accounts, orgs and products
Im currently exploring the design of an account and role based permissions system.
Im trying to look for and find standard patterns (if any) for structuring user accounts, organisations, sub organisations and products.
It would need to handle:
1. Role based permissions
2. Roll up billing
My initial thoughts are:
1. A user account is unique but can be a member of 1 or more organisations.
2. An organisation could have one or more sub organisations.
3. An organisation (or sub organisation) would be subscribed to one or more products
4. A the product level, the user would have role based permissions to provide access to certain features.
How would you best design something like this from a rule / hierarchy perspective?
Would you apply role based permissions at every level for the user?
- sharemywin 4y agoThis has a pretty good discussion how to store hierarchical data: https://tdan.com/modeling-hierarchies/5400 https://tdan.com/modeling-hierarchies/5400 Also, you would need a user_org table for user org relation. probably a subscription table and permission table between product and org(subscriptions) and prod and user(permissions) you might also look at a graph database
- ko3us 4y agoThanks for the reference. This helps me think about the hierarchy of the relationships. So it makes sense to have a user account be a member of an org. Then have orgs have a relationship with products. Im still questioning where I would apply role based permissions. If a user account is a member of an org should I apply the role permission at every level?
- PaulHoule 4y agoIt is a little unusual to allow a user to be part of more than one organization. If you do this you need to carefully separate attributes that belong to the individual person from attributes that have to do with the relationship between a person in the organization. Often we treat the e-mail address as an ‘attribute of the user’ but I might very well want my mail related to organization A to go to my personal account while organization B goes to my organization B email account…. And worse than that it might not entirely be my decision to make.
- necovek 4y agoIn the real world, eg. if your company uses GitHub, and you are a member of multiple free software organizations, well... I would go and say that it is common for a user to be a member of multiple organizations, but that you don't necessarily have to allow for that complexity in the implementation, thereby forcing users to switch between accounts for all of their organizations.
- ko3us 4y agoYes agree. My Github account is linked to multiple organisations. Some of which Im admin, some im just a member of. I agree that It is probably more common and actually a more realistic representation of the real world. My view is that a single identity is a better experience than multiple isolated identities.
- ko3us 4y agoyeah on the surface it does seem strange, however its actually quite normal in the agriculture space where Im working to develop this platform out. For example, we have "farm managers" that are actually members / associated with multiple farms. One Farm manager that helps manage multiple farms owned by different organisations. BTW most of these farms are SME style farms, and thus dont have their own domain and thus dont have unique first.last@uniquedomain.com email address. As a result, users use their personal email address to access the system. But yes, Need to have a one user to many organisation structure.