Organisation structure

There is one organisation structure, shared by the whole app. Find it under Settings → Access → Organisation structure.

Why only one. A roll-up is only arithmetic if every number comes from the same tree, and a person can only have one home unit without being double counted. Per-department or per-workspace trees make group-level reporting impossible to compute and impossible to trust.

First-time setup

When the structure is empty you are offered a set of templates — hierarchical, geographic, functional, product, matrix, flat and others. Pick the one closest to your reporting lines. You can rename levels and change the drawing style afterwards; the template only gives you a starting shape.

Levels

Levels are data, not code. The defaults are Country, Organization, Division, Group, Team, Function, Process, External party, and you can rename, reorder, add or remove them.

Each level carries two switches:

Switch Off means
Can hold grants Nobody can be given access at this level.
Can own objects No register or control library can live here.

Turn can hold grants off for Process and External party. That single setting is what stops somebody accidentally granting a role on a vendor.

Adding and editing units

Select Add unit. Give it a name, a level, a parent, a head and a headcount. Everything else you see on a unit — the risk profile, who can reach it, what it owns — is calculated, not stored.

The canvas view shows the same tree as a chart. You can drag a unit onto a new parent there.

Moves are effective-dated

Dragging a unit does not silently rewrite the tree. It opens a dialog asking for an effective-from date and a reason, and shows an impact preview: what happens to roll-up, to access, and to the objects the unit owns.

The whole app can then be resolved as at any past date. Historic views are read-only, because retro-editing the structure would destroy the only defence you have when an auditor asks who could see what last March.

The matrix line

If your structure allows a second parent, a unit can name a functional line alongside its delivery line — an information security team sitting in a country technology division but professionally accountable to a group InfoSec function.

Grants follow both lines. This is powerful and it is the one setting that can surprise you. After enabling it, check the Access view of the canvas to see what each role now reaches.