Access to SimpleTwo
Applies to: identity 0.35 · Checked: 28.09.2026
identity is the organisation's directory. It may hold thousands of accounts that do not need
SimpleTwo: contractors, service mailboxes, staff who only use company applications through
identity's sign-in. Such an account signs in to the portal /me and to third-party
applications (OIDC, SAML, LDAP), but reaches the SimpleTwo services only once it is assigned
access.
Features
Access is assigned per feature:
| Feature | What it gives | Who provisions it |
|---|---|---|
| Chat and calls | messenger, calls, meetings | messaging |
| Calendar and address books | calendars, invitations, personal books | calendar |
| a mailbox, addresses, JMAP and SMTP | ||
| Drive | files | drive |
| Telephony | an internal number and outside calls | the coordinator |
A feature is assigned to a person or to an identity group, dynamic groups included. A person has a feature when at least one assignment gives it: their own, any of their groups', or the "everyone" option (below). Leaving a group keeps a feature that other assignments give.
Guests, bots, rooms and system accounts belong to the coordinator. Nothing is assigned to them: they reach SimpleTwo as before.
Provisioning state
When a person gets a feature, the service prepares what it needs — a mailbox, a calendar, a chat identity — and reports the result to identity. Each of a person's features has a state:
- pending — assigned, the service has not answered yet;
- active — the service has prepared everything; only from now on does the platform token open that service;
- failed — the last attempt failed, the reason is shown beside it;
- deprovisioning — no longer assigned; the service removes the data under its own retention and reports when it is done.
Where it is in the console
In identity's console /admin:
- People → a person → "Access to SimpleTwo" — every feature: whether the person has it, through what (directly, a group, everyone), its state, its error. Grant and Withdraw manage the direct assignment. Below: the services this person's platform token opens.
- Groups → "Access to SimpleTwo" — a tick for each feature granted to the group.
- Policies → "Access to SimpleTwo" — the switch, the "everyone" option and the counts by state.
Every grant, withdrawal, change of the setting and service report is written to the security event log.
The switch
Provisioning is off by default: every account reaches every service, as before this feature. Assignments and states are kept while it is off, so they can be prepared in advance. While it is off, no service deprovisions anything.
Once it is on:
- the coordinator lists in its directory, and creates, only accounts that are assigned something;
- the platform token opens identity, the coordinator and only the services where the feature is active;
- for people who are assigned nothing, messaging and calendar go to deprovisioning: while provisioning was off, those services served everyone, so they may hold data.
Migration: "everyone gets messaging and calendar"
The "Everyone gets messaging and calendar" option gives every person chat, calls, calendar and address books without separate assignments. The order for a running installation:
- Tick the option and save, without switching on.
- Assign mail, drive and telephony to the groups that need them.
- Switch provisioning on. Nobody loses anything.
- Later, untick the option and move to group assignments.
What the coordinator does with accounts that have nothing
The coordinator removes an account that has no assignments left from its directory not at once but after a grace period (14 days by default, configurable), and only when the person's data is nowhere:
- they never signed in, hold no roles granted in the coordinator's console, and sponsor no guests;
- no service holds their data: no feature is active, failed or deprovisioning.
Everyone else stays, and the coordinator writes the reason to its log. The account stays in identity in every case.
For service developers
GET /v1/provisioning/feed?since=&limit=&feature=— rows by cursor, oldest first:seq,feature,username,assigned,state,changed_at, andmode. Any service reads it with its service token.POST /v1/provisioning/{feature}/{username}/statewith{seq, state, error}— the report of the service that owns the feature:active,failed(with the reason) ordeprovisioned. A report on an outdatedseqis refused with 409.