Roll out Enterprise in the right order
On Enterprise everything is unlocked on day one, so the question is not what Onplana can do but what to turn on first, and what to leave off. This guide is the order, with reasons. It assumes the admin first-week checklist (organization basics, role model, first admins) and sequences the Enterprise rollout on top; every step links the article that does the work, so this page stays a map.
| # | Step | Why this position |
|---|---|---|
| 1 | Currency + working calendar | Projects inherit them at creation; a later change does not rewrite the estate |
| 2 | 2FA + session policies | Enforced before invites, enrollment is part of joining; after, it is an interruption |
| 3 | Permissions preset, custom roles | People should arrive into the right posture, not be corrected after |
| 4 | SSO + SCIM (if you have an IdP) | SCIM provisions the members every later step organizes |
| 5 | Import your estate | Needs steps 1 and 4: projects inherit the foundations, and assignees match by email |
| 6 | Teams | Members and work both exist, so composition is a decision, not a guess |
| 7 | Rate cards, then capacity | Finance and utilization compute from them; hard prerequisite for step 9 |
| 8 | Governance | Skip it below portfolio scale, out loud |
| 9 | Compliance + enforcement | The step with teeth comes last, after adoption and honest numbers |
| - | AI and agents posture | No fixed position; the defaults are safe, review before broad agent adoption |
Currency and working calendar
Section titled “Currency and working calendar”- Set budgets and currency and configure working calendars before you create or import anything. Every project, including every project an import creates, inherits both at the moment it is created; changing the defaults later does not rewrite an estate built on the wrong ones.
Never skip this. Ten minutes here protects everything after it.
Two-factor and sessions
Section titled “Two-factor and sessions”- Enforce two-factor authentication and review session policies while the only people in the workspace are your pilot admins. Enforced now, 2FA enrollment is part of joining; flipped after a broad rollout, it interrupts everyone’s work week.
Session policies can wait. The 2FA switch should not.
Permissions posture, then SSO and SCIM
Section titled “Permissions posture, then SSO and SCIM”-
Understand roles and permissions, then pick the preset that matches your shape: Open for a small collaborative group, Standard for most, Strict or Formal PMO when a project office owns process. Add custom roles now if named roles like Finance Reviewer are part of your model.
-
Configure SSO and provision users with SCIM before you invite anyone at scale. SCIM creates and deactivates the members every later step organizes; wiring it after a hundred manual invitations is the same job done twice.
No identity provider, or running a small pilot? Skip step 4. Email invitations are fine at that scale, and accounts link to SSO later by verified email, so the only thing lost is effort.
Import your estate
Section titled “Import your estate”- Assess your Project Online estate if you are coming from Project Online, then migrate from Project Online or import from Microsoft Project files.
The position is load-bearing on both sides. Not earlier: the importer matches resources to members by email, and unmatched emails become warnings instead of assignments, so an estate imported before its people arrives unowned. Not later: imported projects inherit the step 1 foundations, which is most of the reason step 1 exists.
- Create teams under People, mirroring how the imported estate actually gets worked. Teams feed workload views and per-team capacity, and both are only as meaningful as the team boundaries.
A pilot small enough to be one team can skip this.
Rate cards, then capacity
Section titled “Rate cards, then capacity”- Configure rate cards, split cost and billable rates if you bill for time, then plan team capacity. Earned value, utilization, and every finance view compute from rates and capacity; until these exist, those views are decoration.
Skip the billable split if you never bill clients. Do not skip cost rates if you ever want to know what work costs. Rate cards are also the hard prerequisite for step 9, which refuses to enable without them.
Governance
Section titled “Governance”- Understand the proposal pipeline, set up gate reviewers and evaluation criteria, classify projects as strategic or operational, and stand up the change control board if baseline changes need formal approval.
Skip this below portfolio scale, and say so out loud. Gates and review boards earn their keep when proposals compete for a portfolio’s attention; below that, they are ceremony. A five-person Enterprise pilot should not walk through this section. It composes cleanly with everything already configured when the pipeline develops real contention.
Compliance and enforcement, last
Section titled “Compliance and enforcement, last”- Monitor timesheet compliance in visibility-only mode until the numbers look sane, then enforce with hard-lock if your regime requires it. Wire compliance evidence export and audit log review when auditors enter the picture.
Last because it is the step with teeth: enforcement blocks real work for non-compliant members. It belongs after people know the tool, after rate cards make the numbers honest, and after a soft period where compliance was visible but not enforced. Skip entirely if nobody bills time or answers to an auditor.
AI, agents, and storage
Section titled “AI, agents, and storage”This section has no number because it has no fixed position: unlike every step above, nothing breaks by deferring it, since the defaults are safe. Review it before agents become part of how your teams work.
- Understand your AI token budget. Every plan includes a one-time token bonus rather than a metered bill, so AI spend is bounded by design; there is no runaway-cost switch to worry about on day one. Set the monthly cost cap (warn or block) under AI & Usage once real usage gives you a number to cap.
- Agent action limits and what agents can delete. Destructive agent operations are deny-by-default per organization, so there is nothing to switch off; enabling any of them is a deliberate opt-in to make with your governance posture, not before.
- Read agent activity once you connect external agents, so agent work lands in the same review habits as human work.
- Storage needs no rollout step: the quota is per plan, usage is visible to admins, and there is nothing to configure until you approach it.
Once you are running, this whole area moves to the security and AI posture review, the quarterly companion to this guide: it re-checks access, tokens, agent policy drift, and the cost cap this section deferred.
What to leave off, for now
Section titled “What to leave off, for now”Deferring these is a decision, not neglect; none get harder later:
- Custom navigation, better informed by real usage than by guesses about it.
- The Microsoft Teams app, which lands better once people know the web app it embeds.
- IP allowlisting, a specific compliance posture, not a default hardening step.
- Dashboards, whiteboards, and wikis, which grow out of the work; seeding them empty helps nobody.
For what each plan includes, send people to compare plans and upgrade rather than quoting numbers from memory. The comparison stays current; memory does not.
We already invited everyone by email. Is it too late for SSO? No. Accounts link to your identity provider by verified email, so nobody forks into a duplicate identity. The only cost was effort.
We are a small team on Enterprise for one feature. Does this order still apply? Steps 1 through 5 do, in miniature. Then stop, use the feature you came for, and return for teams, rates, governance, and enforcement when scale demands them. Skipping most of this guide is the correct reading of it for you.
Why is enforcement last when compliance is why we bought Enterprise? Enforcement without adoption produces workarounds, not compliance. Get people working in the tool, make the numbers honest, then give the numbers teeth. Auditors care about the evidence trail, and the trail is better when the data under it is real.
Was this helpful?
Thanks for your feedback!