Manage Access at Organizational Unit (OU)
Last updated
Last updated
This document explains how administrators manage user access at the Organizational Unit (OU) level in Oten Admin, including:
Creating Organizational Units
Managing members within an OU
Applying and inheriting security policies (MFA, Password, Session)
If you are new to Oten Admin, start by understanding the following concepts:
Organizational Units (OU) are used to group users logically (by team, department, or function).
OUs can be structured hierarchically (parent–child relationship).
Security and access policies can be inherited from parent OUs.
To begin, navigate to the Organizational units section in the Admin dashboard.
The purpose of this document is to help administrators:
Organize users into structured units
Manage access and security policies at scale
Reduce manual configuration at the individual user level
Before proceeding, make sure that:
You have Admin or Organization Admin permissions
An Organization and at least one root OU already exist
Users have been created in the system
Log in to Oten Admin
From the left navigation menu, select Organizational units
If the OU does not exist yet:
Newly created OUs inherit policies from their parent by default.
From the OU list, click the OU you want to manage (for example, QC Team)
The OU details panel will open
Open the Members tab
Review the list of users currently assigned to the OU
Click Add member
Search for a user by name or email address
Select the user from the results
Click Add member to confirm
The user will immediately belong to this OU and inherit all applicable policies.
After completing these steps:
The Organizational Unit is properly configured
Users are assigned to the correct OU
Security and access policies are applied automatically
Access management is centralized, consistent, and easy to audit
Click Create org unit
Enter the following information:
Select a Parent Org unit
Click Create org unit to confirm
Open the Policies tab
Review the policies applied to the OU, such as:
Policies may be inherited from the parent OU or customized at this level
Click Edit on a policy to override inherited settings if required
Org unit name
(Optional) Description
MFA policy
Password policy
Session policy