Skip to main content

Organisation structure

Your organisation is the top-level tenant. Within it you create Org Units that mirror your team structure — each with a free-text type label (Domain, Team, Department, Squad, etc.) that is display-only and does not affect access control. Users can belong to multiple Org Units. Each membership is explicit — there is no implicit access from hierarchy or admin roles.

Admin roles

Security policies

Security officers and owners configure organisation-wide policies from Security → Policies:

Access reviews

Access reviews are periodic certification workflows. An admin starts a review, which snapshots all current Org Unit memberships. Each membership is approved (kept) or revoked by a reviewer. Revoked memberships are removed immediately. Access reviews satisfy ISO 27001 Annex A.9 and SOC 2 CC6.2 requirements for periodic access certification. View full access control docs →