We are evaluating ZITADEL for a multi-tenant SaaS application and would like some guidance on the best way to model a hierarchical tenant structure.
Our business model looks like this:
* Parent Organization (Tenant)
* Child Organization / Subsidiary A * Child Organization / Subsidiary B * Child Organization / Subsidiary C
Each child organization should have its own users, roles, and data, but the parent organization should be able to:
* View and manage all child organizations * Access data across all child organizations * Assign administrators at both parent and child levels * Potentially support SSO across the hierarchy
From the documentation, it appears that ZITADEL organizations are flat and there is no built-in parent-child organization hierarchy.
What would be the recommended way to implement this in ZITADEL?
Some specific questions:
1. Should each child organization be created as a separate ZITADEL organization and the hierarchy be maintained in our application database? 2. Are Project Grants intended for this type of scenario? 3. How would you recommend implementing parent-level administrators who can manage multiple organizations? 4. Is there a common pattern or reference architecture for modeling organization hierarchies (parent company → subsidiaries → departments) in ZITADEL? 5. If this is a supported pattern, what are the recommended implementation steps?
Any guidance, best practices, or examples would be greatly appreciated.
Thank you!
Continue the conversation
Join the Discord to ask follow-up questions and connect with the community
Z
ZITADEL
ZITADEL - Identity infrastructure, simplified for you.