When planning your System Tree organization, consider the access requirements of users who must manage the systems.
For example, you might have decentralized network administration in your organization, where different administrators have responsibilities over different parts of the network. For security reasons, you might not have an administrator account that can access every part of your network. In this scenario, you might not be able to set policies and deploy agents using a single administrator account. Instead, you might need to organize the System Tree into groups based on these divisions and create accounts and permission sets.
Consider these questions:
Who is responsible for managing which systems?
Who requires access to view information about the systems?
Who should not have access to the systems and the information about them?
These questions impact both the System Tree organization, and the permission sets you create and apply to user accounts.