---
title: "Policy tiers"
description: "Use Calico Enterprise policy tiers to let platform, security, and app teams author and order policy independently within shared clusters."
product: "Calico Enterprise"
version: "3.23 (latest)"
section: "Network policy"
canonical_url: "https://docs.tigera.io/calico-enterprise/latest/network-policy/policy-tiers/"
---

# Policy tiers

## [📄️Get started with policy tiers](https://docs.tigera.io/calico-enterprise/latest/network-policy/policy-tiers/tiered-policy.md)

[How tiered policy works in Calico Enterprise — evaluation order, pass actions, and using tiers to enforce microsegmentation across teams.](https://docs.tigera.io/calico-enterprise/latest/network-policy/policy-tiers/tiered-policy.md)

## [📄️Change calico-system tier behavior](https://docs.tigera.io/calico-enterprise/latest/network-policy/policy-tiers/calico-system.md)

[Customize the behavior of the calico-system tier that Calico Enterprise installs by default to keep its own components reachable.](https://docs.tigera.io/calico-enterprise/latest/network-policy/policy-tiers/calico-system.md)

## [📄️Network policy tutorial](https://docs.tigera.io/calico-enterprise/latest/network-policy/policy-tiers/policy-tutorial-ui.md)

[Tutorial for the Calico Enterprise policy management UI — author, order, and stage policies inside tiers from the web console.](https://docs.tigera.io/calico-enterprise/latest/network-policy/policy-tiers/policy-tutorial-ui.md)

## [📄️Configure RBAC for tiered policies](https://docs.tigera.io/calico-enterprise/latest/network-policy/policy-tiers/rbac-tiered-policies.md)

[Configure Kubernetes RBAC to control which users can edit Calico Enterprise policies in each tier.](https://docs.tigera.io/calico-enterprise/latest/network-policy/policy-tiers/rbac-tiered-policies.md)
