In Pega's access control hierarchy: Applications reference Access Groups (which define permissions and roles), and Access Groups reference Operator IDs (users). The structure is: Application -> Access Group -> Operator ID. Each level is referenced by the level above it, creating a chain of authorization.