For groups
Separate companies, shared IT, one access picture.
A group is not one organization with sub-folders. It is legal entities with their own boards, budgets and rules — sharing a service desk. The tooling has to hold both facts at once.
Patterns we often see in groups
Nobody owns the whole picture.
An acquisition arrives with its own tenant. A shared service desk gets admin rights in all of them, because that is the only way to work. Two years later nobody can say which company a given account belongs to, or who approved the access it holds.
Cost
Each entity sees its own line.
License and platform cost are allocated per company and per period, so the finance controller in one subsidiary can see what her company actually consumes without asking group IT to build a spreadsheet.
Delegation
Access rules, not admin roles handed out by hand.
A service desk agent may reset passwords in every company but order new hires in one. A local IT lead approves for her entity only. The rule states the approver, and every execution is written to the same record as the request.