---
title: "STACKIT Access Management"
description: "Centralized role-based access control (RBAC) system for fine-grained authorization across STACKIT resources."
scfAsset:
  category: "service"
  managed: false
  marketplaceUrl: "https://marketplace.stackit.cloud/en/products"
  tags: ["IAM", "Access Management", "RBAC", "Security"]
  maintainers:
    - user: "alexander.gabert"
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/stackit/stackit-service-access-management/"
source_file: "docs/architecture/assetcontainer/stackit/stackit-service-access-management.mdx"
---

STACKIT Access Management provides centralized authorization management across all cloud services and projects.

## Service Overview
- **Least Privilege Access**: Enables granular permission assignments to users, groups, and service accounts.
- **Compliant Governance**: Structured, auditable permission inheritance across organizations, folders, and projects.
- **Included Core Platform**: Delivered as an integral platform feature at zero additional cost.

## Technical Details
- **Architecture**: Separates authentication (IdP) from authorization (IAM).
- **Role Scopes**: Predefined platform standard roles alongside support for custom role definitions.

## Limitations & Constraints
- **Top-Down Inheritance**: Permission inheritance is top-down; granular sub-project denies cannot override parent grants.

<LinkCard title="STACKIT Access Management Documentation" href="https://docs.stackit.cloud" />
