Person → role → everything else follows.
The role model is the heart of just IDM: describe once what a role means — which access groups, teams, mailboxes and which license belong to it. From then on, you maintain roles, not groups.
Roles instead of one-off permissions
A role bundles access, teams, mailboxes and the license recommendation. Change the role, and everyone carrying it changes with it — memberships are computed, not maintained by hand.
Bulk assignment
Department move, reorganization, new project: give or revoke a role for many people at once — in seconds, not in ticket loops.
Recommendations built in
Every role knows its recommended license, add-ons and security classification — and who owns it. New employees start fully equipped.
No ghost groups
Access groups that teams, channels or mailboxes still point to cannot be deleted. Orphaned permissions never come into existence.
Turn “we should clean that up someday” into “done and documented.”
Two ways in, one goal: talk for 30 minutes — or try it yourself in a test instance with sample data.
30-minute call · test instance with sample data · no obligation