Skip to main content
OpenFGA allows you to grant a group of users access to a particular object.
When to useRelationship tuples are helpful when you want to specify that a group of users all have the same relation to an object. For example, OpenFGA allows you to:
  • Grant a group of engineers viewer access to roadmap.doc
  • Create a block_list of members who can’t access a document
  • Share a document with a team
  • Grant viewer access to a photo to followers only
  • Make a file viewable for all users within an organization
  • Manage access to a database for users in a certain locale

Before you start

Familiarize yourself with basic OpenFGA Concepts before you continue. In the example below, you have the following authorization model with two types:
  • company that can have an employee relation
  • document that can have a reader relation.

In addition, the following concepts are important to group access management:

Modeling user groups

OpenFGA allows you to add users to groups and grant groups access to an object. For more information, see User Groups.

OpenFGA concepts

  • A Type: a class of objects that have similar characteristics
  • A User: an entity in the system that can be related to an object
  • A Relation: a string defined in the type definition of an authorization model that defines the possibility of a relationship between an object of the same type as the type definition and a user in the system
  • An Object: represents an entity in the system. Users’ relationships to it can be define through relationship tuples and the authorization model
  • A Relationship Tuple: a grouping consisting of a user, a relation and an object stored in OpenFGA

Step by step

01. Adding company to the document

The following Relationship Tuple assigns ever employee of a type company a reader relationship with a particular object of type document, in this case document:planning): Every employee in the company can read document:planning

02. Add an employee to the company

Below is a relationship tuple specifying that Anne is an employee of company:xyz:

03. Checking an individual member’s access to an object

Call the Check API to verify that Anne can read document:planning returns true: The same check for Becky, a different user, returns false, because Becky does not have an employee relationship with company:xyz: Check the following sections for more on how to model group.

Modeling User Groups

Learn about how to model users and groups.

Managing Group Membership

Learn about managing group membership.
Last modified on September 28, 2026