# Application Permissions / Groups

**URL:** <https://forum.keycloak.org/t/application-permissions-groups/6425>\
**Category:** Getting advice\
**Created:** [December 15, 2020, 4:17pm UTC](https://forum.keycloak.org/t/application-permissions-groups/6425 "2020-12-15T16:17:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hollo34](https://avatars.discourse-cdn.com/v4/letter/h/ba9def/32.png) [@Hollo34](https://forum.keycloak.org/u/Hollo34)\
**Post date:** [December 15, 2020, 4:17pm UTC](https://forum.keycloak.org/t/application-permissions-groups/6425/1 "2020-12-15T16:17:09Z")

</div>

Hello Community !

I am lead developer at **AOS** and I need some advices for a specific _integration_.

**AOS** is a startup in the building industry and it’s help professionals to communicate with contractors during the construction of the building  
Link =\> [AOS Website](https://www.go-aos.io/)

Note that we have already implemented **Keycloak** for _authentication_ and it’s working fine !

Let’s come back to the point, I need to build a strong _system_ for creating groups with users and permissions ( _global permission, permission by project, group of permission and so on_ ) and i see features that can do the job (group, client, client scope, autorization etc)

Example:

A professional is managing four agencies and he needs to see / manage and modify them

We have to create a binary tree like system in order to manage group and permission

**Technical information**

**Agency** is composed of _users_  
**Users** can be in several agencies in the same time  
**Users** have different _roles_ (_admin, intern and guest_)  
Each _roles_ have specific permissions

Global _permission_ is working on all _project_ where _users_ are in, but we can modify permissions for a specific project if we want, it will overlaid permission only in this project

**For example:** a intern doesn’t have the right to see answers from the contractor, on a test project, admin can give him the right to do it

Child agency can be parent agency and you go below the tree and so on

So we can have Agency France -\> South Agency -\> { Agency1, Agency2, Agency3 }

We are looking for the best solution in order to do that, so if someone of the community have a good idea to do it correctly with KeyCloak, could be great 🙂 (msg, call, mail etc)

We want to implement the solution with all the power **Keycloak** can deliver 😉

I am looking forward to speaking with you !

Alain

---

<div class="post-metadata">

**Author:** ![bhaskardabhikof](https://avatars.discourse-cdn.com/v4/letter/b/45deac/32.png) [@bhaskardabhikof](https://forum.keycloak.org/u/bhaskardabhikof)\
**Post date:** [December 29, 2022, 12:39pm UTC](https://forum.keycloak.org/t/application-permissions-groups/6425/2 "2022-12-29T12:39:15Z")

</div>

Did you find anything?
