Skip to content
Status

AI Control Plane · Orgs, Projects and Team

Orgs, Projects and Team

How organizations and projects structure the platform, and how to manage members, roles, and invites from the Team page.

Organizations and projects are the two levels of structure in the platform. This page explains how to think about them, and covers the Team page, where organization members, roles, and invites are managed.

Viewing the Team page requires the org:read scope, which both the Admin and Member default roles include. Sending invites, changing roles, and removing members require the org:admin scope, held by Admins only.

An organization is the company-level tenant, and most companies need exactly one. Everything about people and governance lives at the organization level: membership, roles and permissions, SSO and Directory Sync, billing, security policies, and audit logs. Members join the organization, not individual projects.

A project is a workspace inside the organization that scopes the tool surface: sources, toolsets, MCP servers, environments, skills, and deployments all belong to a project. Every organization starts with a default project, which cannot be deleted.

Staying on the default project is the right call for most teams; create additional projects when separation starts to matter:

  • Different teams or products need their own tool catalogs, MCP servers, and environments.
  • Credentials need a boundary. Environments and their secrets are scoped to a project, so a project keeps one team’s credentials out of another team’s toolsets.
  • Usage should break down by team. Tokens and costs attribute to the organization through its projects, so a project per team gives per-team views in Observe and Billing on top of the org-wide totals.

The Team page lists everyone in the organization and handles invites, role changes, and removals. Open it from Organization settings > Team in the dashboard.

The Team Members section lists every member with their join date, roles, and last activity. Search by name or email; each row’s menu has actions for that member, including Manage roles, Remove from the organization, and shortcuts for security challenges.

The Team Members list with joined dates, role badges, last activity, and the Invite Member button

The page guards against lockouts. Removing the last remaining admin is blocked, and members cannot remove themselves from the list.

The Invite Member button opens a dialog with an Email address field. When RBAC is enabled, the dialog also includes a role select for choosing the role the new member receives. Click Send Invite to submit.

When Directory Sync (SCIM) is enabled, a banner notes that members are provisioned and roles assigned from the identity provider, not from this page, and links to the identity settings. See the IDP and SSO page for setup details.

The Pending Invites section lists invitations that have been sent but not yet accepted. Each pending invite supports resending the invitation, changing the assigned role, and revoking the invite.