Build a Departments Structure

IMPORTANT: Follow this guide after you have configured your User Groups and Custom Roles.

Departments in your VPAM server enable you to create an additional segmentation layer that mirrors your organization's operational structure. While User Groups determine what applications Standard Users can see, and Roles determine what actions users can perform, Departments determine organizational boundaries for applications, approvals, vendors, gateways, and administrative visibility.

This guide contains recommendations and implementation models to help System Administrators build a secure and scalable Department structure in VPAM.

The goal of this guide is to enable zero-trust access control through:

  • Organizational segmentation

  • Granular approval routing

  • Department-level visibility restrictions

  • Separation of duties

  • Controlled vendor management

  • Application ownership segmentation

This document is intended for VPAM System Administrators responsible for designing secure operational boundaries in their server.

Initial Considerations

Departments are an advanced segmentation layer in VPAM and are not required for every deployment. However, they become extremely valuable when organizations require:

  • Segmentation between teams or business units

  • Department-based approvals

  • Delegated administration

  • Vendor isolation

  • Granular access boundaries

  • Environment separation

  • Organizational scalability

Departments affect:

  • Users

  • Roles

  • Applications

  • Gateways

  • Gatekeepers

  • Vendors

  • Approval workflows

IMPORTANT:
Departments do not replace User Groups or Roles. Departments complement them as a third layer of segmentation. The recommended implementation order is:
  1. Create User Groups
  2. Configure Custom Roles and Permissions
  3. Build the Departments Structure

Understanding Department Segmentation

The VPAM server includes the built-in Global department.

BEST PRACTICE:
Use the Global department for System Administrators only by not assigning it to Standard Users.

System Administrators inherently have visibility into all departments and resources in the server. Assigning operational users to the Global department reduces segmentation effectiveness and weakens zero-trust enforcement.

Departments primarily enable VPAM administrators to:

  • Restrict access boundaries

  • Route approvals

  • Separate applications

  • Isolate vendors

  • Segment gateways and gatekeepers

  • Mirror organizational ownership structures

Where to Begin

To configure Departments in the new UI:

  1. Navigate to User Management.

  2. Open Departments.

  3. Click Add, on the left-most column of the Global department.
    All the departments you create are sub-departments of Global.

  4. Build the department hierarchy according to your organization's structure.

Departments can contain sub-departments, enabling hierarchical segmentation models.

Suggested Department Structures

Use one or more of the following implementation models to create a scalable and secure Department structure.

Assigning Departments

After building the Department hierarchy, continue assigning departments to your VPAM resources.

Department-Based Approval Routing

Departments significantly improve Approval Workflows in VPAM.

Recommendations

Ensure that you also follow the following recommendations when implementing Departments.

  • DO

    • Implement Departments only after configuring User Groups and Roles.

    • Keep the Global department reserved for System Administrators.

    • Use Departments to mirror operational ownership.

    • Combine multiple segmentation strategies when appropriate.

    • Use Departments to isolate production environments.

    • Use Departments to isolate vendor access.

    • Align Applications, Vendors, and Approvers within the same department.

    • Use Department segmentation to simplify approval routing.

    • Keep Department names clear and purpose-driven.

    • Build hierarchies that are easy to understand operationally.

  • DON'T

    • Don't use Departments as a replacement for User Groups.

    • Don't use Departments as a replacement for Roles.

    • Don't place all resources into the Global department.

    • Don't create unnecessary Department complexity.

    • Don't mix unrelated environments in the same department.

    • Don't create deeply nested hierarchies unless operationally required.

    • Don't assign production and development systems to the same department.

    • Don't configure vendors in departments unrelated to the applications they support.

Remember!

  • Departments are most effective when they reflect operational ownership, support approval workflows, and enforce organizational boundaries. Ensure you complement User Groups and Roles.

  • Not every VPAM deployment requires highly granular Departments. However, organizations with multiple teams, vendors, environments, or approval workflows typically benefit significantly from implementing a Department structure.

  • Build Departments with operational clarity in mind. If administrators cannot easily understand the purpose of a department, the structure is likely too complex.