Thanks for the reference.
This helps me think about the hierarchy of the relationships.
So it makes sense to have a user account be a member of an org.
Then have orgs have a relationship with products.
Im still questioning where I would apply role based permissions.
If a user account is a member of an org should I apply the role permission at every level?