About This Architecture
Multi-site LDAP Directory Information Tree (DIT) organizing users, roles, and applications across Belgium and France geographic regions. The hierarchy branches from root dc=pstb_g1,dc=fr into geographic organizational units (ou=BE, ou=FR), then subdivides by site location, personnel type, job function (filiere, metier), and application access groups. Users like uid=prof.dupont inherit role-based attributes (enseignant, IT, etudiant) and are dynamically linked to application access groups (cn=acces-learn, cn=acces-office365) via dashed membership lines. This structure demonstrates best-practice LDAP design for federated identity management across multiple locations, enabling scalable role-based access control (RBAC) and simplified user provisioning. Fork this diagram on Diagrams.so to customize organizational units, add new sites or applications, or export as .drawio/.svg for documentation and compliance audits. The separation of geographic, functional, and application branches allows independent scaling of each dimension without restructuring the entire tree.