- Entity hierarchy must mirror the legal structure, not the org chart.
- SSO and automated provisioning are usually non-negotiable requirements.
- Delegated administration determines whether finance scales or becomes a bottleneck.
- Procurement and security review are part of the evaluation, not an afterthought.
- Consolidated reporting has to survive currency and calendar differences.
Entity structure comes first
The first enterprise question is whether the platform models legal entities properly. Not departments, not regions — entities, each with its own accounts, its own reporting obligations and its own approvals.
Where a platform only models one entity with tags for the rest, everything downstream becomes a workaround: intercompany allocation, statutory reporting and audit all suffer.
- Each entity has its own accounts, cards and settlement arrangements.
- Approval chains can differ per entity where local requirements demand it.
- Reporting rolls up to a group view without losing entity-level detail.
- Intercompany transactions are identifiable rather than merged into the consolidated total.
Identity, SSO and provisioning
At enterprise scale, an account that exists outside the identity provider is a security finding waiting to happen. Single sign-on ensures access follows employment status automatically, and automated provisioning ensures cards and permissions do too.
The detail that matters most is deprovisioning. When someone leaves the identity provider, their platform access — and ideally their card — should be revoked without a separate manual step.
- SAML or OIDC single sign-on with enforced use, not optional.
- Automated provisioning and, critically, deprovisioning of users.
- Role mapping from identity groups so permissions follow the org structure.
- Break-glass administrative access documented and monitored.
Delegated administration
A central finance team cannot issue every card in a company of several thousand people. Delegation moves routine administration to the people closest to the need, inside limits that finance controls.
Well-designed delegation is bounded and auditable: a delegate can act only within a ceiling, only for their own scope, and every action is logged.
- Delegates act within a spend ceiling set centrally.
- Scope is limited to their own entity, department or cost centre.
- All administrative actions are logged with actor and timestamp.
- Delegation itself can be revoked centrally at any time.
What procurement and security will ask
Preparing these answers early shortens enterprise evaluations considerably.
| Area | Typical question |
|---|---|
| Security certification | Which independent audits or certifications are held, and how current are the reports? |
| Data residency | Where is data stored and processed, and can that be constrained by region? |
| Access control | How is administrative access granted, reviewed and revoked? |
| Business continuity | What are the recovery objectives, and when was the plan last tested? |
| Subprocessors | Who else processes our data, and how are changes notified? |
| Exit | How is data exported if the relationship ends, and in what format? |
Consolidated reporting that survives reality
Group reporting has to reconcile entities that use different currencies, occasionally different fiscal calendars, and always different local practices. The platform's job is to preserve the detail needed to do that correctly rather than flattening it early.
The specific thing to test during evaluation is whether the original transaction currency and rate are retained alongside the reporting currency. Where they are not, variance analysis becomes impossible to explain.
Frequently asked questions
It varies by provider and plan. Because enterprise security policy typically requires it, establish availability and cost early rather than discovering it during contracting.
Mirror the legal structure. Modelling entities as tags on a single organisation creates statutory reporting and intercompany problems that get worse as the group grows.
As few people as practical, with delegation for routine tasks and a documented break-glass procedure. Administrative access should be reviewed on a schedule, not only when someone leaves.
Deprovisioning. Provisioning gets tested during rollout because people notice when access does not work; deprovisioning fails silently and is discovered during an access review.
Keep reading
Sources and further reading
Every factual statement on this page is checked against primary documentation. Terms change frequently, so confirm details with the provider before acting on them.
- Brex — official website Primary source for current product names, availability and terms.
- Brex legal and platform agreements Issuer disclosures, program agreements and regulatory statements.
- NIST Digital Identity Guidelines (SP 800-63B) Technical basis for our descriptions of MFA, passkeys and authenticator strength.
- FASB Accounting Standards Codification Reference point for accrual, expense recognition and close-process statements.