This article is aimed at global pilots and CISOs who wish to structure their organization in Tenacy at the start of their license. Modeling your organization is one of the most structurally important decisions of your deployment: it determines your reporting, the management of your users' rights, and the use of your licenses. Take the time to design it before you start creating objects in the solution.
The basic objects of a model
The root
The root is the top of your organizational tree. Its name corresponds to the name of your Tenacy account. A pilot attached to the root has all rights in the solution; a contributor attached to the root can be assigned objects across all perimeters.
The grouping
A group allows you to consolidate several perimeters to consolidate reporting and manage access rights. A local pilot on a group only sees objects attached to the perimeters of that group. A contributor on a group can only be assigned objects on the perimeters that make it up.
💡 Groups are unlimited and can be nested into sub-groups to refine your tree structure.
The internal perimeter
The perimeter is the central object in Tenacy: this is the level at which all objects in the solution are assigned (actions, measures, recurring tasks, risks, gaps, incidents, exemptions). It has a security baseline, a compliance score, and a Trusted Score.
A perimeter can represent a BU, a subsidiary, a country, a critical application, an IS, a supporting asset, or any entity on which you wish to manage security.
⚠️ The number of internal perimeters is subject to licensing.
Supplier and application perimeters
Supplier and application type perimeters are unlimited and do not consume any perimeter license quota. They have a simplified functional model: assessment on a policy, simple actions, and reporting in a dashboard. They do not have a security baseline, which means that only the declarative score is available for these types of perimeter.
⚠️ You can only create applications if you have the Security in Projects module activated.
Modeling your organization: procedure
From the Organization menu, hover over the root and click the + button to add your first element. Select the type of object you want (group, internal perimeter, supplier, application).
💡 If you want to use groups, start by creating them before inserting the relevant perimeters.
Secondary trees
Tenacy allows you to create an unlimited number of secondary trees. A secondary tree can reuse already existing perimeters to organize them according to a different logic from the main tree, without creating new perimeters or duplicating data.
Secondary trees serve two main purposes:
Rights management: giving certain users a restricted view of a subset of perimeters, organized differently from the main tree.
Cross-cutting reporting: building consolidated views that cut across several entities along a different axis (by product, by criticality level, by type of applicable regulation, etc.).
🚫 In a secondary tree, click on Existing element to place already created perimeters. Clicking on New perimeter creates an additional perimeter that consumes a license.
Using groupings for cross-cutting reporting
Groups in a tree allow you to consolidate perimeters to facilitate your reporting. For example:
Groups by geographic zones (France, Germany, Italy)
Groups by type of activity (Production, R&D, Support) or by level of regulatory requirement (NIS2 entities, non-NIS2 entities)
Compliance scores and the Trusted Score are automatically recalculated at each group level, allowing you to obtain a consolidated view along any reporting axis without modifying your main structure.
💡 The same perimeter can appear in several secondary trees simultaneously, with different groups in each. Its security data remains unique and shared across all views.
5 standard configurations
There is no universal model in Tenacy. Here are five generic configurations to help you identify the one that best fits your context.
Configuration 1 — Flat structure: a few perimeters directly under the root, without groups. Suited to smaller organizations with a limited number of entities to manage and simple reporting needs.
Configuration 2 — Geographic tree: perimeters are grouped into groups by country or region. Suited to multi-site organizations where local managers oversee the security of their territory and global pilots consolidate at group level.
Configuration 3 — Tree by BU or business domain: perimeters represent activities or business lines, grouped into functional groups. Suited to organizations whose security perimeters follow a product or service logic rather than geography.
Configuration 4 — Mixed tree with secondary trees: the main tree follows the legal or geographic structure, and one or more secondary trees organize the same perimeters along other axes (regulatory, criticality, IS type). This is the most flexible configuration for complex organizations.
Configuration 5 — Single perimeter with suppliers and applications: a single internal perimeter for the organization's IS, supplemented by a set of supplier and application perimeters to manage the subcontracting chain. Suited to smaller structures that also want to manage their third-party risk.
Impact of the model on your licenses
Your Tenacy license defines a quota of internal perimeters. Here are the key rules to keep in mind:
Internal perimeters consume the license quota. Each new internal perimeter created reduces the available quota, whether it is active in a tree or not.
Supplier and application perimeters are unlimited and do not consume any quota.
Groups are unlimited and do not consume any quota.
Secondary trees are unlimited. Placing an existing perimeter in a secondary tree does not consume any additional quota. However, creating a new perimeter from a secondary tree does consume a license.
Pilots have a separate quota. A deactivated user continues to count toward this quota; only archiving releases it.
💡 Before creating new perimeters, check your available quota with your Tenacy administrator or your commercial contact.
Aligning your model with your external tools
Modeling your organization in Tenacy has a direct impact on how connectors and external tools integrate with it. A few points to keep in mind:
Connectors (Jira, etc.) are configured at the register level, which is itself attached to a perimeter. If your Tenacy perimeters do not match the projects or spaces in your external tool, synchronization will be difficult to maintain.
Imports and exports (actions, measures, recurring tasks) are always associated with a perimeter via its identifier. A poorly named or poorly structured perimeter complicates mass operations.
Shared dashboards with external teams (IT management, executive leadership) must be able to target perimeters or groups that are stable over time. Avoid frequently renaming or moving the nodes that serve as the basis for these reports.
💡 If your organization uses an external asset repository (CMDB, subsidiary directory, IS mapping), align the names and identifiers of your Tenacy perimeters with those of this repository as much as possible to facilitate cross-referencing.
Expected result
A well-designed model allows you to:
manage compliance and risks at the right level of granularity;
manage your users' access rights without multiplying accounts;
produce consolidated reports along the axes that matter to your leadership;
optimize your license consumption by avoiding the creation of unnecessary perimeters.
Frequently asked questions
What is the difference between a group and a perimeter? A group is used solely to structure the tree and consolidate reporting: no security object can be directly assigned to it. A perimeter is the operational entity to which all objects (actions, measures, risks, etc.) are assigned and which has a security baseline and scores.
Can I modify the structure of my organization after deployment? Yes, but certain operations (merging perimeters, moving) require migrating objects manually. See the article Preparing and launching the reorganization of your tree structure in Tenacy for the complete procedure.
Can a perimeter appear in multiple trees? Yes. A perimeter can be present in the main tree and in one or more secondary trees simultaneously. Its security data is unique and shared across all views.
How many secondary trees can I create? The number of secondary trees is unlimited.
How do I know if I am approaching my perimeter quota? Contact your Tenacy administrator or your commercial contact to find out your quota and your current consumption.
Can I delete a group without losing the perimeters it contains? No, not directly. You must first move or reassign all the perimeters and sub-groups contained in the group before you can delete it.
