More and more organisations consist of multiple business units. Think of a holding company with subsidiaries, a corporation with divisions, or a service provider that manages compliance for several brands. They want one central compliance environment — but with a watertight separation between the units. The new Business Units feature in uComply makes exactly that possible, without compromising on security.
The problem: one environment, several realities
A large organisation usually wants two things at once. On one hand, central control: the same standards (ISO 27001, for example), one set of controls and a group-wide overview for the CISO. On the other hand, local autonomy: each business unit manages its own risks, incidents and assets, and that data need not — and often must not — be visible to the other units.
Until now you mostly had to choose between two awkward options. Either you gave each business unit its own environment — expensive, fragmented and hard to steer centrally. Or you put everything in one environment and accepted that everyone could see everyone else's data — a real audit and privacy risk.
Business Units removes that dilemma. One uComply environment, several strictly separated compliance workspaces, with central standards that remain shared.
Separation at the platform level, not in the app
The key thing to understand: the separation is not a filter inside the uComply app. uComply relies on the native security model of Microsoft Dataverse — business units, security roles and record ownership. Dataverse enforces those authorisations at all times, at the data level.
That distinction is crucial for enterprise organisations. A risk entered by an employee of business unit A is invisible to business unit B — even if someone tries to reach that data by another route: through their own Power App, the Excel connection, a Power BI report or directly via the API. The boundary does not shift with the tool someone uses. It is the same Microsoft security model that Dynamics 365 runs on.
For an auditor that is a strong story: the data isolation is not a promise made by the application, but a property of the underlying platform.
Three roles, one clear structure
The setup follows the familiar Dataverse tree. At the top sits the root business unit — the holding company itself, with the holding staff and the group CISO. Below it you create a dedicated business unit for each part of the organisation.
From solution version 1.0.0.215 onwards, uComply ships three roles that fit this structure precisely:
| Role | For whom | What it sees and can do |
|---|---|---|
| Basic user (BU) | employee of a business unit | works with their own compliance data, strictly within their own business unit |
| Security Officer (BU) | security officer of a unit | full management of risks, incidents and assets — only within their own business unit |
| Holding CISO | group CISO or corporate auditor | read access across all underlying business units, for the group overview |
The existing uComply roles remain unchanged. Organisations working with a single environment today notice nothing of the update until they set up the business units themselves.
How it works in practice
Take a holding company with two subsidiaries: North and South.
Everyone gets exactly the view that suits their role — the shop floor locally, the board at a glance.
Shared standards, separated working data
The separation applies to operational data: risks, incidents, assets, evidence, improvement actions and the like. The reference data — standards, clauses and the control set — remains visible to everyone. This way every business unit works against the same standard, without having to duplicate or maintain that standard per unit.
If you work with several organisations in one environment, an organisation filter appears automatically on the list screens. Handy for holding users who can access everything: with one click you zoom in on a single unit. The real separation is independent of this — Dataverse handles it through the roles, filter or no filter.
Who is this for?
Business Units is built for organisations with multiple departments or entities that take compliance seriously:
In all these cases you get central control and local separation, instead of one or the other.
Would you like to see how uComply makes compliance manageable for an organisation with multiple units?



