VNCdirectory
The directory control plane: the single system of record for tenants, org units, people, seats, entitlements and access across the suite.
One identity across everything
VNCdirectory is the directory control plane for the whole suite: the single system of record for tenants, org units, people, placements, seats, external parties, products and features, access grants and audit. Every other product is a projection of what the directory publishes, so access and org structure are modelled once. It is multi-tenant, deny by default, and it never treats an existing directory as the source.
- ✓Single system of record: tenants, org units, people, placements, seats, grants, audit
- ✓Multi-tenant with strict isolation and unbounded org trees
- ✓Seats as the billable entitlement, with a lifecycle and a seats-in-use widget
- ✓Feature-level entitlements, checked at runtime
- ✓Access grants that widen visibility, deny by default
- ✓One identity for the whole suite, with silent single sign-on
User management
Full lifecycle: onboarding, role changes, access reviews and offboarding, with seats, licensing and DSAR erasure.
Org units, placements and roles
Typed units (company, sub-organization, region, branch, division, department, team) in an unbounded tree; placements attach a person to a unit with a role; role tiers carry per-role entitlements.
Single sign-on
One identity for the whole suite; the directory publishes the identity claims every product uses to authenticate and scope data. Sign-in is OIDC, with SAML where an app needs it.
Directory and identity projection
The directory publishes identity, one-way, to the identity service and the directory protocol; VNCdirectory stays the source of truth.
Multi-tenant by design
Many autonomous tenants, each with its own org tree, domains and seats, with strict isolation; external parties are parallel trees.
Access grants
The only way to widen visibility across a boundary, deny by default; a grant names a grantee, a resource and an effect, checked at runtime.
Seats
The canonical billable entitlement, one per person per tenant, with active, suspended and retained states and a live seats-in-use widget.
Unified search and AI substrate
A shared content index for cross-app linking and search, a model registry for the suite AI, and a gateway so agents act with the caller permissions.
One identity for the whole suite
No repeated logins across products.
The system of record
Access and org structure are modelled once, and every product projects them.
Granular permissions
Feature-level entitlements, not just application-level on or off.
Multi-tenant, deny by default
Org trees, seats and explicit access grants.
Model: system of record for tenants, org units, people, seats, grants, audit · Tenancy: multi-tenant, strict isolation, unbounded org trees · Access: role tiers, feature entitlements, access grants, deny by default · Identity: OIDC sign-on, SAML where an app needs it, one identity
Integrated across the suite · single sign-on via VNCdirectory
The suite
Identity, entitlements and the shared search and AI substrate for the whole suite.