SSO and roles: deploy Octowise across the organization
Microsoft Entra ID per instance, granular finance/compliance/building permissions: access governance follows portfolio structure.
Octowise Team
Rolling Octowise out across an organization means aligning identity and rights with portfolio structure, not creating a second directory. Each organization connects its Microsoft account and a catalog of roles: buildings, finance, invoices, and compliance are not inherited automatically.
Microsoft sign-in, web and mobile
Each organization configures its own Microsoft sign-in. Users already in the directory do not get an extra Octowise password. Local accounts remain possible depending on the deployment, but the target model for multi-site organizations is the enterprise directory.
The same identity is used in the browser and on the phone. You do not manage two access regimes.
Separate permissions by role
Reading buildings does not open invoices. Invoice read and write are distinct rights. Compliance, data sources, and dashboards follow the same logic: you compose the role by job, you do not grant “the whole portfolio” by default.
New rights must be attached explicitly. That is deliberate: an existing deployment does not open finance by itself.
- Microsoft sign-in configurable per organization.
- Same account on web and mobile.
- Separate roles for buildings / finance / invoices / compliance.
- Integration keys under the same model.
The org chart as a boundary
Rights combine with portfolio attachment: a territory manager sees their branch, not the whole group. The org chart is therefore not only a visual; it is an authorization and reporting grain.
Scoped users and integration keys share that discipline. An MCP agent is not “more powerful” than a human: it is limited by the key.
Governance and revocation
Revocable keys, adjustable roles, centralized SSO: people leave, change jobs, and access is removed without hunting passwords in integrator files.
That is the prerequisite for opening OData and MCP in production. Without this governance, opening the API is a risk, not an ecosystem.