Organization
User and access administration — creating team members, assigning page and action permissions, and reviewing per-user activity.
At a glance
| Route | /organization |
| Group | Admin |
| Page permission | organization |
What it is
User and access administration for the tenant: creating and managing team members, assigning page and action permissions, resetting passwords, and reviewing per-user activity.
Who it is for
Organisation administrators and IT teams responsible for who can do what.
How it works
Each user carries an explicit grant of page permissions and action permissions, bounded by what the subscription plan includes.
The permissions catalogue exposes the full set of 27 page permissions and 69 action permissions with their entitlement labels — so you assign capabilities in product terms rather than internal identifiers.
Features
- User creation, editing, and deletion
- Per-user page and action permission assignment
- Permissions catalogue with entitlement labels and category grouping
- Administrative password reset
- Per-user activity review
- Team snapshot summarising the current access posture
- Organisation-level analytics including an optimisation view
How to use it
Review the permissions catalogue before adding users
So the grant model is understood in product terms.
Create users with the minimum permission set their role requires
Permissions are easier to add than to justify removing.
Reserve the dangerous write permissions
Particularly approvals.decide, integrations.execute_remediation, and the autopilot.*
family — for the small number of people accountable for changes to the estate.
Use the team snapshot periodically
To review who holds elevated permissions, rather than waiting for an audit to ask.
Move to SCIM at enterprise scale
Managing users by hand does not survive organisational change. See Identity & SSO.
Why it matters
Two-layer permissions mean access can be granted precisely. A finance analyst can be given every read surface in the product without any ability to change cloud infrastructure.
That precision is what allows a cost platform to be opened to finance and leadership rather than restricted to a small platform team — which is usually the difference between a FinOps programme that spreads and one that stalls.
Connects to
- Permissions bounded by the plan in Membership
- Federated provisioning in Identity & SSO
- Workspace lifecycle in Workspace Setup
- Activity recorded in Audit Logs
- Full catalogue in Reference → Permissions