OrgAccess: A Benchmark for Role Based Access Control in Organization Scale LLMs
Debdeep Sanyal, Umakanta Maharana, Yash Sinha, Hong Ming Tan, Shirish Karande, Mohan Kankanhalli, Murari Mandal

TL;DR
This paper introduces OrgAccess, a benchmark to evaluate Large Language Models' ability to understand and operate within organizational role-based access control hierarchies, revealing significant performance gaps in complex permission scenarios.
Contribution
The paper presents a synthetic, comprehensive benchmark for testing LLMs on organizational RBAC tasks, highlighting their limitations in complex, hierarchical permission reasoning.
Findings
GPT-4.1 achieves only 0.27 F1-score on hardest tasks
LLMs struggle with complex, conflicting permissions
Performance degrades with increased permission complexity
Abstract
Role-based access control (RBAC) and hierarchical structures are foundational to how information flows and decisions are made within virtually all organizations. As the potential of Large Language Models (LLMs) to serve as unified knowledge repositories and intelligent assistants in enterprise settings becomes increasingly apparent, a critical, yet under explored, challenge emerges: \textit{can these models reliably understand and operate within the complex, often nuanced, constraints imposed by organizational hierarchies and associated permissions?} Evaluating this crucial capability is inherently difficult due to the proprietary and sensitive nature of real-world corporate data and access control policies. We introduce a synthetic yet representative \textbf{OrgAccess} benchmark consisting of 40 distinct types of permissions commonly relevant across different organizational roles and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsBusiness Law and Ethics · Employer Branding and e-HRM · Knowledge Management and Sharing
