Groups often start with “one OA for every company” or the opposite—“each company buys a disconnected suite.” Either can be right. It depends on which seal a contract uses, whether salary can be seen across entities, and whether HQ needs spot checks.
Write isolation on data scope, not “don’t join that group”
Verbal isolation will leak. Permissions that follow the role survive transfers; see How clear permissions cut disputes and leaks and Why verbal permission rules eventually fail. HQ should receive overdue approvals, over-permission seals, and contract renewals—not every subsidiary leave request. Audit samples drill the org tree; see What role OA plays in audit and compliance.
You do not need one database per company. One back office, different org nodes and data scopes, is enough. Admins can share role templates so each entity does not invent a dialect. If a contract is countersigned across legal entities, add an “entity” field on the lane; see Sales, delivery, and finance share contracts: how to split the back office.
Write share-versus-isolate as a field list: customer names may be group-searchable; unit price and salary default to isolated; policy templates can be pushed down; approval instances are not mutually visible. When a subsidiary closes or merges, the node archives—accounts deleted should not erase tickets. Ticket numbers in old tenders and audit files should still open.
DaXi lists legal entities, who can see rollups, and which fields are absolutely isolated before forms. Go to the Management systems service page and describe the org. If management metrics need a group dashboard, that can connect to Dashboards & Data Platform. How decisions move once a back office exists: see With vs. without a management back office: how decisions actually move.