While it is mandatory to obtain an eID via eIAM, the use of eIAM's access management is optional, i.e. permissions such as roles and attributes can also be assigned elsewhere, for example in the target application or middleware or, as is often the case, using granular access: high-level in eIAM's access management, low-level in the target application. In eIAM's access management, permissions can be modelled via units, profiles, roles and attributes.