# Org Admin

Organization settings sit above projects and govern everything shared across them: membership and roles, billing, domains, telemetry configuration, and identity. The org home itself is a projects dashboard, with search, favorites, per-project audit activity, and admin shortcuts to create projects, invite members, and define roles.

Members with organization read access can view most of these pages; configuration is reserved for organization admins. Each page below states its exact requirements.

## Sections

### [Collections](/docs/ai-control-plane/org-admin/collections)

Reusable groups of MCP servers and skills, installable into multiple projects in one go.

### [Team](/docs/ai-control-plane/org-admin/team)

Organization membership: members, roles, and pending invites.

### [Billing](/docs/ai-control-plane/org-admin/billing)

Usage against the plan's allowances, and payment management for self-serve tiers.

### [API Keys](/docs/ai-control-plane/org-admin/api-keys)

Scoped keys for programmatic access: consumer, producer, chat, hooks, and device-agent enrollment.

### [Custom Domain](/docs/ai-control-plane/org-admin/custom-domain)

Serve MCP servers from a branded domain, with DNS verification and an optional IP allowlist.

### [Logging & Telemetry](/docs/ai-control-plane/org-admin/logging-and-telemetry)

The switches that power [Observe](/docs/ai-control-plane/observe): tool-call logging, tool I/O capture, session capture, fail-open behavior, and OTEL forwarding.

### [AI Integrations](/docs/ai-control-plane/org-admin/ai-integrations)

Optional provider compliance and admin APIs (Cursor, Anthropic, OpenAI) that enrich usage, spend, and review data.

### [Webhooks](/docs/ai-control-plane/org-admin/webhooks)

Webhook delivery for platform events (preview).

### [Audit Logs](/docs/ai-control-plane/org-admin/audit-logs)

The organization-wide audit feed of who changed what, with expandable diffs.

### [Device Agent](/docs/ai-control-plane/org-admin/device-agent)

The on-device agent that enforces required plugins and MCP configuration across every assistant (beta).

### [Roles & Permissions](/docs/ai-control-plane/org-admin/roles-and-permissions)

Role definitions, scope grants, member assignments, and authorization challenges.

### [MCP Connections](/docs/ai-control-plane/org-admin/mcp-connections)

Active OAuth connections agents hold into MCP servers, with bulk revocation.

### [IDP and SSO](/docs/ai-control-plane/org-admin/identity)

Single Sign-On and Directory Sync with the organization's identity provider.

### [Remote Identity Providers](/docs/ai-control-plane/org-admin/remote-identity-providers)

Upstream OAuth issuers that authenticate MCP clients, organizational or project-scoped.
