core suite

VNCdirectory

The directory control plane: the single system of record for tenants, org units, people, seats, entitlements and access across the suite.

✓Central identity for the whole suite, as a single system of record
✓Publishes identity one-way to the identity service and the directory protocol
✓Provisioning and role management, with seats and entitlements
✓Multi-tenant with org trees, seats and access grants, deny by default
Overview

One identity across everything

VNCdirectory is the directory control plane for the whole suite: the single system of record for tenants, org units, people, placements, seats, external parties, products and features, access grants and audit. Every other product is a projection of what the directory publishes, so access and org structure are modelled once. It is multi-tenant, deny by default, and it never treats an existing directory as the source.

  • ✓Single system of record: tenants, org units, people, placements, seats, grants, audit
  • ✓Multi-tenant with strict isolation and unbounded org trees
  • ✓Seats as the billable entitlement, with a lifecycle and a seats-in-use widget
  • ✓Feature-level entitlements, checked at runtime
  • ✓Access grants that widen visibility, deny by default
  • ✓One identity for the whole suite, with silent single sign-on
Features & highlights

User management

Full lifecycle: onboarding, role changes, access reviews and offboarding, with seats, licensing and DSAR erasure.

Org units, placements and roles

Typed units (company, sub-organization, region, branch, division, department, team) in an unbounded tree; placements attach a person to a unit with a role; role tiers carry per-role entitlements.

Single sign-on

One identity for the whole suite; the directory publishes the identity claims every product uses to authenticate and scope data. Sign-in is OIDC, with SAML where an app needs it.

Directory and identity projection

The directory publishes identity, one-way, to the identity service and the directory protocol; VNCdirectory stays the source of truth.

Multi-tenant by design

Many autonomous tenants, each with its own org tree, domains and seats, with strict isolation; external parties are parallel trees.

Access grants

The only way to widen visibility across a boundary, deny by default; a grant names a grantee, a resource and an effect, checked at runtime.

Seats

The canonical billable entitlement, one per person per tenant, with active, suspended and retained states and a live seats-in-use widget.

Unified search and AI substrate

A shared content index for cross-app linking and search, a model registry for the suite AI, and a gateway so agents act with the caller permissions.

Why it's different

One identity for the whole suite

No repeated logins across products.

The system of record

Access and org structure are modelled once, and every product projects them.

Granular permissions

Feature-level entitlements, not just application-level on or off.

Multi-tenant, deny by default

Org trees, seats and explicit access grants.

Model: system of record for tenants, org units, people, seats, grants, audit · Tenancy: multi-tenant, strict isolation, unbounded org trees · Access: role tiers, feature entitlements, access grants, deny by default · Identity: OIDC sign-on, SAML where an app needs it, one identity

Works with
The suiteVNCdirectory · 1 live integrations

Integrated across the suite · single sign-on via VNCdirectory

The suite

Identity, entitlements and the shared search and AI substrate for the whole suite.

Ready to run VNCdirectory on your own infrastructure?