> ## Documentation Index
> Fetch the complete documentation index at: https://docs.altoura.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Organization & RBAC

> Every Altoura customer is added as an Organization within Altoura and users are added to the Organization. These users are assigned roles using Altoura's role-based access system (Altoura RBAC). Altoura RBAC is an authorization system that helps manage and control access to the various resources within Altoura.

## Altoura RBAC

<Info>
  ### The following roles are part of the Altoura RBAC system:

  ### OrgAdmin Role

  ### PortalAccess Role

  ### AppAccess Role

  ### ProjectAccess Role
</Info>

<img src="https://mintcdn.com/altoura-785c3552/pvN_b_9fLlPnvtUQ/images/docs/13d5249-image.png?fit=max&auto=format&n=pvN_b_9fLlPnvtUQ&q=85&s=f26cb7e4f7743726a3f4ae9e5cf2ca94" alt="" width="572" height="449" data-path="images/docs/13d5249-image.png" />

### OrgAdmin Role

1. Altoura Users that are assigned the **OrgAdmin** Role can create other users within the Organization.
2. They can assign roles to these users including the OrgAdmin role.
3. They can modify the roles assigned to a user.
4. They can delete users in the Organization.

### PortalAccess Role

1. Altoura Users that are assigned the **PortalAccess** Role can log in to the Altoura Portal as authors and create entities within the Altoura Portal.
2. They have access to all the Projects, Experiences, Objects created within the Organization in the Altoura Portal.
3. They can create and view all the reports under Altoura Analytics.

### AppAccess Role

1. Altoura Users that are assigned the **AppAccess** Role can login to the Altoura Client on all devices.
2. They have read access to all the projects and experiences created under the Organization.

### ProjectAccess Role

1. Altoura Users that are invited to Projects are assigned the ProjectAcsess Role.
2. They can log in to the Altoura Client and access the project/experience they have been invited to.
3. These users will not be able to access the other projects created within the Organization.

<Warning>
  ### Notes:

  The permissions within a role cascade downwards, for e.g.

  1. An Altoura OrgAdmin will be able to access the Altoura Portal and the Altoura Client.
  2. Altoura users with PortalAccess will be able to access the Altoura Client and view all the projects.
</Warning>
