The scope hierarchy, and what inherits down it
Management groups sit above subscriptions, so a policy or role assignment made once there is inherited by every subscription beneath. A working shape is management groups by department, containing subscriptions by environment, containing resource groups by workload - which lets each control be applied at the level it actually belongs to. Both Azure Policy assignments and RBAC role assignments can be scoped precisely to a single resource group, granting exactly the intended reach instead of a broader administrative role over the subscription.