Skip to main content

Access to SimpleTwo

Applies to: identity 0.35 · Checked: 28.09.2026

identity is the organisation's directory. It may hold thousands of accounts that do not need SimpleTwo: contractors, service mailboxes, staff who only use company applications through identity's sign-in. Such an account signs in to the portal /me and to third-party applications (OIDC, SAML, LDAP), but reaches the SimpleTwo services only once it is assigned access.

Features​

Access is assigned per feature:

FeatureWhat it givesWho provisions it
Chat and callsmessenger, calls, meetingsmessaging
Calendar and address bookscalendars, invitations, personal bookscalendar
Maila mailbox, addresses, JMAP and SMTPmail
Drivefilesdrive
Telephonyan internal number and outside callsthe coordinator

A feature is assigned to a person or to an identity group, dynamic groups included. A person has a feature when at least one assignment gives it: their own, any of their groups', or the "everyone" option (below). Leaving a group keeps a feature that other assignments give.

Guests, bots, rooms and system accounts belong to the coordinator. Nothing is assigned to them: they reach SimpleTwo as before.

Provisioning state​

When a person gets a feature, the service prepares what it needs — a mailbox, a calendar, a chat identity — and reports the result to identity. Each of a person's features has a state:

  • pending — assigned, the service has not answered yet;
  • active — the service has prepared everything; only from now on does the platform token open that service;
  • failed — the last attempt failed, the reason is shown beside it;
  • deprovisioning — no longer assigned; the service removes the data under its own retention and reports when it is done.

Where it is in the console​

In identity's console /admin:

  • People → a person → "Access to SimpleTwo" — every feature: whether the person has it, through what (directly, a group, everyone), its state, its error. Grant and Withdraw manage the direct assignment. Below: the services this person's platform token opens.
  • Groups → "Access to SimpleTwo" — a tick for each feature granted to the group.
  • Policies → "Access to SimpleTwo" — the switch, the "everyone" option and the counts by state.

Every grant, withdrawal, change of the setting and service report is written to the security event log.

The switch​

Provisioning is off by default: every account reaches every service, as before this feature. Assignments and states are kept while it is off, so they can be prepared in advance. While it is off, no service deprovisions anything.

Once it is on:

  • the coordinator lists in its directory, and creates, only accounts that are assigned something;
  • the platform token opens identity, the coordinator and only the services where the feature is active;
  • for people who are assigned nothing, messaging and calendar go to deprovisioning: while provisioning was off, those services served everyone, so they may hold data.

Migration: "everyone gets messaging and calendar"​

The "Everyone gets messaging and calendar" option gives every person chat, calls, calendar and address books without separate assignments. The order for a running installation:

  1. Tick the option and save, without switching on.
  2. Assign mail, drive and telephony to the groups that need them.
  3. Switch provisioning on. Nobody loses anything.
  4. Later, untick the option and move to group assignments.

What the coordinator does with accounts that have nothing​

The coordinator removes an account that has no assignments left from its directory not at once but after a grace period (14 days by default, configurable), and only when the person's data is nowhere:

  • they never signed in, hold no roles granted in the coordinator's console, and sponsor no guests;
  • no service holds their data: no feature is active, failed or deprovisioning.

Everyone else stays, and the coordinator writes the reason to its log. The account stays in identity in every case.

For service developers​

  • GET /v1/provisioning/feed?since=&limit=&feature= — rows by cursor, oldest first: seq, feature, username, assigned, state, changed_at, and mode. Any service reads it with its service token.
  • POST /v1/provisioning/{feature}/{username}/state with {seq, state, error} — the report of the service that owns the feature: active, failed (with the reason) or deprovisioned. A report on an outdated seq is refused with 409.