Account and organization
Organizations and roles
An organization isolates its domains, files, networks, invoices, and integrations.
#Overview
An organization isolates its domains, files, networks, invoices, and integrations.
#Roles and separation of duties
Owners and admins control sensitive settings; members operate day-to-day resources; viewers remain read-only. Billing, webhooks, alert channels, and BYOC tokens can require owner/admin even when the resource is visible.
An invitation carries a role and expires according to service policy. Once accepted, the member receives access only to the current organization; role changes apply to subsequent requests.
#Manage a member
Invite their address from Organization.
Assign the least role compatible with the work.
Verify acceptance and expected access.
Reduce the role or remove the member when the work ends.
#Permissions by role
| Action | owner | admin | member | viewer |
|---|---|---|---|---|
| View members, invitations, and summary | Read | Read | Read | Read |
| Edit organization and billing identity | Allowed | Allowed | No | No |
| Invite, remove, or change member/viewer users | Allowed | Allowed | No | No |
| Assign or manage an admin | Allowed | No | No | No |