Organizations and members
Organizations as tenants, roles, invitations, knowledge, secrets and how members are counted against a plan.
Managed cloudSelf-hosted
The organization is the tenant: projects, tasks, workers, capabilities, secrets and the audit log belong to it.
Organization ids come from verified membership, never from requests, and every query is scoped; non-members get
404, so ids cannot be probed.
Roles
| Role | Typical use |
|---|---|
OWNER | Billing and everything else |
ADMIN | Settings, integrations, capabilities, members |
MANAGER | Projects and tasks for a team |
DEVELOPER | Create and follow tasks |
VIEWER | Read only |
Users cannot grant roles above their own. The dashboard only mirrors permissions; the API enforces them.
Invitations
Settings → Members: invite by email. People without an account get a single-use link (valid seven days) that lets them register even when registration is closed; re-inviting replaces the link. Invitations can be revoked.
On the managed cloud, pending invitations count towards your plan's member limit, like members.
Knowledge and secrets
- Settings → General → knowledge: background every agent in the organization receives.
- Secrets: encrypted with AES-256-GCM, only ever shown masked, referenced as
secret:NAMEby integrations, capabilities and environment profiles. Each delivery to a worker is audited.
Audit log
An append-only log of security-relevant actions: members, roles, settings, secrets (by name), approvals, capability installations and more.