ST-2026-196 · Authentication & identity
Auth0 adds organization-level roles in Early Access
Auth0 announced Organization-Level Roles in Early Access on 29 July 2026, allowing roles, permissions and assignments to be scoped independently to a specific Auth0 Organization while leaving tenant-level RBAC unchanged.
Previous state
Auth0 Organizations relied on tenant-wide roles or customer-specific workarounds for the organization-scoped role model described by the announcement.
Current state
Organizations can define and manage their own role definitions, permissions and user or enterprise-group assignments through the announced Early Access capability.
Affected users
Who needs to care
Auth0 tenants using Organizations that need authorization roles scoped independently to individual customer organizations.
Required response
What to do
Treat organization-level roles as Early Access and validate role definitions, permissions and invitation/group assignment behavior before replacing established authorization logic.
Evidence boundary
What the source does not prove
The source proves Early Access for organization-scoped roles and states that existing tenant-level RBAC is unchanged. It does not establish general availability or mandatory migration from tenant-level roles.
Lifecycle history
Dated event sequence
- Organization-level roles enter Early Access
Auth0 announced organization-scoped roles in Early Access.
Evidence ledger
First-party sources
- 01Auth0 — Organization-Level Roles - Early Access
Official Auth0 changelog · 2026-07-29
Open official source ↗