RoleOptic

New Security access, license demand, and governed What-If in one decision platform

See what really drives yourD365F&SCM license cost

RoleOptic connects D365F&SCM roles, duties, privileges, resources, and access levels to base and attach license demand, so finance and security teams can make controlled decisions before production changes.

Access graph

Users, roles, duties, privileges, resources, and environments.

Base + Attach

License families traced back to security access drivers.

What-If + Approval

Scenario evidence before production security changes.

Product proof

See the D365F&SCM security model move.

RoleOptic transforms D365F&SCM security complexity into clarity by guiding teams from a license level back to the roles, duties, privileges, resources, and access paths that created it.

Role Mind MapRoleOptic
RoleOptic Role Mind Map recording showing D365F&SCM security nodes expanding through access and license evidence.
D365F&SCM security exportsBase and attach license logicTenant-scoped ingestionWhat-If scenario evidenceApproval-ready recommendationsTelemetry and OData syncD365F&SCM security exportsBase and attach license logicTenant-scoped ingestionWhat-If scenario evidenceApproval-ready recommendationsTelemetry and OData sync

Continuous D365F&SCM governance loop

Turn every license decision into a governed improvement cycle.

RoleOptic guides enterprise teams through the rhythm behind responsible D365F&SCM change: establish the evidence, rehearse the decision, measure the business impact, and govern what moves forward.

1

Plan

Do

Plan

Create the access evidence model

Begin with a reliable view of D365F&SCM security: who has access, how roles inherit duties and privileges, which resources they reach, and which license families those paths create.

Enterprise valueFinance, security, and architecture start from the same evidence before any recommendation is made.

Get D365F&SCM data

Bring D365F&SCM security evidence into RoleOptic

Load security evidence through an Electronic Report export or a governed OData connection. RoleOptic turns the raw access structure into a traceable model for licensing decisions.

Data ingestion

Load D365F&SCM security data the way your team operates

Use a controlled file upload for a first baseline, or connect through OData when the team is ready for recurring refreshes.

Planned RoleOptic capture showing Electronic Report upload and OData synchronization options for D365F&SCM security ingestion.

Do

Simulate change before D365F&SCM changes

Move from observation to action without touching production. Try user, role, and optimization scenarios against the baseline before any access is changed in D365F&SCM.

Enterprise valueSecurity teams can test remediation ideas while finance sees the potential license effect before implementation.

What-If

Rehearse controlled security changes

Create a scenario, adjust user or role access, and keep the proposed change separate from the current D365F&SCM baseline.

User What-If

Test access changes for one user

Model a user-level change and see whether the license position moves before touching D365F&SCM production security.

RoleOptic User What-If scenario view showing proposed D365F&SCM security changes.
3

Check

Act

Check

Measure financial exposure, risk, and usage

Turn the scenario into a reviewable business decision. Compare license demand, owned inventory, What-If results, risk signals, and telemetry evidence before the action moves forward.

Enterprise valueEvery cost or risk statement can point back to the access evidence that created it.

What-If result

Read the outcome before approval

Compare the proposed scenario with the baseline so reviewers understand license movement, cost exposure, and access impact before the decision advances.

What-If analysis

See the scenario result in business terms

Review the baseline-versus-proposed license position so finance, security, and application owners can evaluate the change from the same evidence.

Planned RoleOptic What-If cost analysis capture showing baseline versus proposed license demand.
4

Act

Plan

Act

Govern and implement approved changes

Move approved decisions into controlled work. Preserve the evidence, guide implementation, and keep the decision trail ready for audit and the next governance cycle.

Enterprise valueLicense optimization becomes a repeatable operating practice, not a one-time cleanup project.

Approval

Turn recommendations into controlled work

Preserve the scenario evidence, approval trail, and implementation guidance so the path from recommendation to action is clear.

Approval Workflow

Route high-impact changes through review

Move a scenario into approval with the evidence reviewers need to understand cost, risk, and access impact.

Planned RoleOptic approval workflow recording showing a What-If scenario moving through review.

Enterprise data protection

Your D365F&SCM evidence stays governed from sign-in to decision.

RoleOptic is designed to protect the sensitive security evidence behind licensing, audit, and remediation. Identity is verified, customer boundaries are established before data access, sensitive identifiers are encrypted before storage, and each decision remains tied to a traceable evidence trail.

Verified enterprise identityCustomer-isolated accessEncrypted sensitive labelsGoverned evidence lifecycle
Security architectureProtection follows the data

Authenticated access to governed evidence

  1. Verified identity

  2. Tenant context

  3. Protected labels

  4. Protected at rest

  5. Traceable evidence

01

Verified identity and tenant membership

Microsoft Entra External ID confirms identity before RoleOptic maps the user to customer membership and grants tenant-scoped access.

02

Tenant context with defense-in-depth isolation

RoleOptic establishes tenant context at the application layer; explicit customer filters then work with PostgreSQL Row Level Security and a default-deny database context.

03

Protected labels and identifiers

Sensitive user and security labels are encrypted before storage using AES-256-GCM envelope encryption, wrapped data keys, and tenant-scoped blind indexes.

04

Protected at rest with controlled key exposure

Sensitive labels remain ciphertext at rest, while unwrapped data keys are limited to the active request or job and cleared from the scoped crypto context.

05

Traceable evidence integrity

SHA-256 file fingerprints, protected ingestion integrity fields, and immutable approval history help preserve a defensible evidence trail.

06

Governed operations

Tenant-scoped jobs, sanitized responses, scoped processing, and audited lifecycle actions keep operational evidence connected to oversight.

Key management

Choose the custody model that fits your security policy.

RoleOptic separates tenant data encryption keys from the provider responsible for wrapping them, so key custody can be evaluated as its own enterprise control.

RoleOptic custody

Platform-managed keys

RoleOptic uses a dedicated key-management boundary for wrapping tenant data keys. The production provider, custody model, and operating evidence are confirmed before customer data is activated.

Customer custody

Azure Key Vault BYOK

Enterprise customers can configure their own Azure Key Vault and validate the key identifier plus wrap and unwrap permissions before production activation.

Security capabilities are presented from the current RoleOptic architecture. Production key custody, deployment evidence, and customer-specific controls are confirmed during enterprise security review.

Microsoft Entra External IDExplicit tenant scopingPostgreSQL FORCE RLSAES-256-GCMEnvelope encryptionTenant blind indexesScoped DEK handlingTamper-evident audit metadataAzure Key Vault BYOK validationAudited data lifecycleMicrosoft Entra External IDExplicit tenant scopingPostgreSQL FORCE RLSAES-256-GCMEnvelope encryptionTenant blind indexesScoped DEK handlingTamper-evident audit metadataAzure Key Vault BYOK validationAudited data lifecycle

Subscription plans

Choose the governance operating model that fits today.

Every plan keeps the D365F&SCM security-to-license story clear. Capacity, ingestion, optimization depth, and implementation access expand with the operating model.

Paid subscriptions open at production launch. The hosted staging environment is available for controlled validation, while the Free Demo remains available for evaluation.
Evaluate the product safely

Free Demo

$0no cost

A synthetic D365F&SCM workspace for seeing how RoleOptic makes the security-to-license relationship understandable.

  • Synthetic demo dataset
  • No customer environments
  • No customer data upload
  • Preloaded historical trends
Focused D365F&SCM teams

Essentials

$149per month

A focused, governed starting point for teams that need reliable license and access visibility.

  • 1 Production + 1 Sandbox environment
  • Up to 200 active users
  • Manual ER upload
  • Core optimization and ER XML download
Available at launch
Enterprise-scale D365F&SCM governance

Enterprise

$1,499per month

For organizations that need scale, Azure Key Vault BYOK, and the complete implementation package library.

  • Unlimited environments and users
  • Azure Key Vault BYOK
  • OData, telemetry, and approval workflow
  • ER XML, X++, and Data Management packages
Available at launch
RoleOptic plan comparison
CapabilityFree DemoEssentialsProfessionalEnterprise
Production environmentsDemo only13Unlimited
Sandbox environmentsDemo only13Unlimited
Active usersDemo only2001,000Unlimited
OData sync allowanceNot includedNot included4 per dayUnlimited
Customer environment ingestionNot includedManual ER uploadManual ER upload + ODataManual ER upload + OData
OptimizationExplore demo evidenceCoreCore + AdvancedCore + Advanced
Telemetry optimizationNot includedNot includedIncludedIncluded
Approval WorkflowIncludedIncludedIncludedIncluded
Implementation packagesNot includedER XMLER XML, X++, Data ManagementER XML, X++, Data Management
Key managementPlatform-managedPlatform-managedPlatform-managedAzure Key Vault BYOK
SupportSelf-serviceStandard business-hours supportPriority business-hours supportEnhanced support and escalation

"Unlimited" reflects the current plan entitlement policy. Paid checkout is available only from the production marketing deployment and requires the corresponding deployed Stripe price mapping.

Frequently asked questions

Evaluate with the details that matter.

Does the Free plan use real customer data?

No. Free is built around a synthetic D365F&SCM dataset so teams can explore the product without uploading production exports.

How does RoleOptic ingest D365F&SCM security information?

Paid plans support manual ER upload. Professional and Enterprise also include D365F&SCM OData profile and synchronization capabilities.

Can we evaluate a role change before making it?

RoleOptic supports User and Role What-If scenarios so teams can inspect projected license impact before altering live assignments.

What does BYOK mean in RoleOptic?

Enterprise includes the Azure Key Vault BYOK capability. Security teams should validate their Azure Key Vault permissions and deployment requirements as part of onboarding.

Which plan includes ongoing governance?

Professional and Enterprise include the OData, telemetry, advanced optimization, and Approval Workflow capabilities used for continuous governance.

Can an enterprise purchase through Stripe?

Enterprise can use the configured checkout path when an Enterprise Stripe price is deployed. The signup flow also supports a procurement-assisted enterprise contact path.