Hi folks, im strugliong to model something, not is just me not being to get my head around. The use case is I have the concept or organization units which are organised in a tree with multiple levels and then users can be linked to each level. And by default users with a manage users role could manage users at the same level they attached too or any child org units. And this is all good and pretty straightfoward with parent relation. The bit im strugling is that we also something like a permission boundary that be associated to the and limit the user permissions only to certain org units that are part of that permissions boundary. Not sure that makes sense... any ideas how I could model that? I tryed a few things but strugling with the fact that the boundary is linked to use and i can't say something like
the orgunit is contained in the boundary linked to self user