For groups

Separate companies, shared IT, one access picture.

A group is not one organization with sub-folders. It is legal entities with their own boards, budgets and rules — sharing a service desk. The tooling has to hold both facts at once.

Patterns we often see in groups

Nobody owns the whole picture.

An acquisition arrives with its own tenant. A shared service desk gets admin rights in all of them, because that is the only way to work. Two years later nobody can say which company a given account belongs to, or who approved the access it holds.

One workspace across every company in the group — switch tenant in the top bar, keep the same rules.

Cost

Each entity sees its own line.

License and platform cost are allocated per company and per period, so the finance controller in one subsidiary can see what her company actually consumes without asking group IT to build a spreadsheet.

IT chargeback by period, allocated per company.

Delegation

Access rules, not admin roles handed out by hand.

A service desk agent may reset passwords in every company but order new hires in one. A local IT lead approves for her entity only. The rule states the approver, and every execution is written to the same record as the request.

Access rules matrix: who may request, who approves, what is logged.