← All work

Enterprise / Connected applications

Toro Suite

Ecosystem
Auth, Management & Planner
Identity
Microsoft Entra / SSO
Status
Ongoing development

One suite. A shared way to work.

Connecting sign-in, application management and operational planning for teams working with Microsoft accounts.

Suite overview / Select a component to explore its responsibility

01 / The starting point

The work was connected. The tools needed to be.

Workforce needs can arrive in Teams before they become official records in Mokas. Meanwhile, accommodation and transport planning depend on spreadsheets and local knowledge.

The documented problem is the gap between these sources: changing dates, different demand versions and limited visibility into the capacity already available. The suite is being developed around a shared identity and focused applications with clear responsibilities.

Starting point

Scattered context

Teams messages Spreadsheet planning Separate business records

Product direction

Shared context

Structured demand Visible resource capacity Controlled connections to Mokas

02 / Shared identity

One identity. Access with intent.

Toro Suite Auth provides a central sign-in service, including support for Microsoft Entra. Applications connect through OAuth/OIDC and keep their own application sessions.

Signing in and having access are separate decisions. A user needs an active grant for the application, and protected requests validate the session and permissions centrally.

Identity → Application grant → Permission

The account identifies the person. The grant defines where they can work.

03 / Operational planning

Plan around people, places and capacity.

Planner brings workforce demand, accommodation and transport into a common project context. Living units, beds and vehicles have their own capacity and availability, rather than being permanently assigned to one project.

The implementation is organized around domain responsibilities: living units, transport, workforce demand and project planning. A controlled server-side connection to Mokas supplies project and workforce context.

Demand

Retain the project, department and changing operational need.

Resources

Understand living-unit and transport capacity in its own right.

Planning

Bring demand and resources together in a date-aware view.

04 / Suite management

A suite that can grow one application at a time.

Management Center owns the application registry: names, canonical URLs, visibility and lifecycle. Registered applications can be discovered across the suite without manually updating every application’s navigation.

It also provides management workflows for application and service-client access, while the central Auth service remains responsible for identity and token issuance.

Application registry+

Register an application, its environment, display information and approved callback URLs. Activation makes it discoverable; access still requires a grant.

Service-to-service access+

Manage which application can call a target API, with explicit permission scopes and an audit trail for changes.

Separate deployment responsibility+

Deployment infrastructure continues to own builds, domains and application-specific configuration. Management Center registers the deployed application.

05 / Current scope

A foundation for connected operations.

The current project brings together central authentication, suite management and ongoing Planner development. The value is in connecting those responsibilities without losing the rules each application needs to own.

Occupancy, utilization and cost analysis are part of the documented broader direction. Development continues across the suite and its planning workflows.