# Plan-wise Access Management Features


This reference provides a complete breakdown of Access Management feature availability and limits across all RudderStack plans.

{{< announcement >}}
Advanced features like customizable baseline workspace policy, unlimited groups, and granular resource and PII permissions are available in the [Enterprise](https://www.rudderstack.com/enterprise-quote/) plan only.
{{< /announcement >}}

## Overview

| Feature | Free | Growth | Enterprise |
| :------- | :---- | :------ | :---------- |
| [Member management](#member-management) | <i class="fa-solid fa-circle-check fa-xl" style="color: #2F965D;"></i><br/><br /><span style="color: #4D4DFF;font-size:15px;">Limited to 10 members per organization</span> | <i class="fa-solid fa-circle-check fa-xl" style="color: #2F965D;"></i><br/><br /><span style="color: #4D4DFF;font-size:15px;">Unlimited members</span> | <i class="fa-solid fa-circle-check fa-xl" style="color: #2F965D;"></i><br/><br /><span style="color: #4D4DFF;font-size:15px;">Unlimited members</span> |
| [Configurable Workspace Default Policy](#workspace-default-policy) | <i class="fa-solid fa-circle-xmark fa-xl" style="color: #2E2E2E;"></i> | <i class="fa-solid fa-circle-xmark fa-xl" style="color: #2E2E2E;"></i> | <i class="fa-solid fa-circle-check fa-xl" style="color: #2F965D;"></i> |
| [Groups](#groups) | <i class="fa-solid fa-circle-xmark fa-xl" style="color: #2E2E2E;"></i> | <i class="fa-solid fa-circle-check fa-xl" style="color: #2F965D;"></i> <br/><br /><span style="color: #4D4DFF;font-size:15px;">Limit of 3 groups per organization</span> | <i class="fa-solid fa-circle-check fa-xl" style="color: #2F965D;"></i><br/><br /><span style="color: #4D4DFF;font-size:15px;">Unlimited groups</span> |
| [Granular resource permissions](#granular-permissions) | <i class="fa-solid fa-circle-xmark fa-xl" style="color: #2E2E2E;"></i> | <i class="fa-solid fa-circle-xmark fa-xl" style="color: #2E2E2E;"></i> | <i class="fa-solid fa-circle-check fa-xl" style="color: #2F965D;"></i> |
| [Granular PII access controls](#pii-access-controls) | <i class="fa-solid fa-circle-xmark fa-xl" style="color: #2E2E2E;"></i> | <i class="fa-solid fa-circle-xmark fa-xl" style="color: #2E2E2E;"></i> | <i class="fa-solid fa-circle-check fa-xl" style="color: #2F965D;"></i> |

## Member management

All RudderStack plans include [member management]({{< ref "access-management/member-management.md" >}}) capabilities with different limits.

### Member limits

| Plan | Member limit | 
| :---- | :----------- | 
| Free | 10 members per organization | 
| Growth | Unlimited | 
| Enterprise | Unlimited |

### Available roles

All plans include the following organization roles:

| Role       | <div style="width:350px">Access</div> |
| :--------- | :------- |
| Admin  | Full organization access. |
| Member | Effective set of permissions within a workspace, computed by aggregating: <br /><br /><ul><li>[Baseline Workspace Policy]({{< ref "access-management/baseline-workspace-policy.md" >}})</li><li>[Group Workspace Policies]({{< ref "access-management/groups.md" >}}) that the member is a part of</li><li>[Member Workspace Policy]({{< ref "access-management/members.md" >}}) configured for the member</li></ul> |

## Groups

Groups enable creation of custom roles and streamline permissions configuration for large teams.

| Plan | Availability | Group limit | 
| :---- | :----------- | :---------- | 
| Free | <i class="fa-solid fa-circle-xmark fa-xl" style="color: #2E2E2E;"></i> | Not available | 
| Growth | <i class="fa-solid fa-circle-check fa-xl" style="color: #2F965D;"></i> | 3 groups per organization |
| Enterprise | <i class="fa-solid fa-circle-check fa-xl" style="color: #2F965D;"></i> | No limit | 

## Baseline Workspace Policy

{{< warning >}}
Admins in the **Free** and **Growth** plans will see a greyed out **Baseline Workspace Policy** tab with the following message: 

"[Upgrade](https://www.rudderstack.com/pricing/) to access this feature and additional capabilities."
{{< /warning >}}

[Baseline Workspace Policy]({{< ref "access-management/baseline-workspace-policy.md" >}}) allows Admins to configure the default workspace policy beyond view-only access for all members.

| Plan | Availability | <div style="width:350px">Notes</div> |
| :---- | :----------- | :------------------------ |
| Free | <i class="fa-solid fa-circle-xmark fa-xl" style="color: #2E2E2E;"></i> | Admins **cannot** configure the Baseline Workspace Policy |
| Growth | <i class="fa-solid fa-circle-xmark fa-xl" style="color: #2E2E2E;"></i> | Admins **cannot** configure the Baseline Workspace Policy |
| Enterprise | <i class="fa-solid fa-circle-check fa-xl" style="color: #2F965D;"></i> | Admins can configure the Baseline Workspace Policy |

## Granular resource permissions

Granular permissions let Admins control access to specific resources within your workspace.

| Plan | Availability | <div style="width:250px">Resource selection</div> | <div style="width:250px">Access to future resources</div> |
| :---- | :----------- | :---------------- | :--------------- |
| Free | <i class="fa-solid fa-circle-xmark fa-xl" style="color: #2E2E2E;"></i> | **Select all** and **Include all future resources** are selected by default and cannot be toggled off | Automatic inclusion |
| Growth | <i class="fa-solid fa-circle-xmark fa-xl" style="color: #2E2E2E;"></i> | **Select all** and **Include all future resources** are selected by default and cannot be toggled off | Automatic inclusion |
| Enterprise | <i class="fa-solid fa-circle-check fa-xl" style="color: #2F965D;"></i> | Admins can select specific resources and choose whether to include future resources | Configurable |

Admins in **Free** and **Growth** plans will see the individual resources greyed out with only the option to select/deselect all resources, as seen in the below image. The toggle for giving access to any new resources created in the future will be enabled by default and it can't be toggled off.

{{< image src="images/access-management/plan-wise-features/granular-resource-permissions.webp" alt="Granular resource permissions" >}}

## Granular PII access controls

{{< announcement >}}
The ability to [configure PII permissions]({{< ref "access-management/policies-overview.md#pii-permissions" >}}) is available in the [Enterprise](https://www.rudderstack.com/enterprise-quote/) plan only.

**Free** and **Growth** plan users will have all PII permissions by default.
{{< /announcement >}}

PII (Personally Identifiable Information) access controls let you restrict access to sensitive data features, ensuring compliance with data regulations like SOC2, GDPR, CCPA, and HIPAA.

With granular PII access controls, Admins will see the **PII** section with the option to configure PII permissions for specific resources, as seen in the below image.

{{< image src="images/access-management/plan-wise-features/granular-pii-permissions-new.webp" alt="Granular PII permissions" >}}

## References

- [Access Management Overview]({{< ref "access-management/overview.md" >}})
- [Member Management]({{< ref "access-management/member-management.md" >}})
- [Baseline Workspace Policy]({{< ref "access-management/baseline-workspace-policy.md" >}})
- [Group Workspace Policies]({{< ref "access-management/groups.md" >}})
- [Member Workspace Policy]({{< ref "access-management/members.md" >}})
- [RudderStack Pricing](https://www.rudderstack.com/pricing/)

<br />
