Browse documentation

Set up your workspace and team

An organization is the shared workspace for your people, policies, credentials, inventory, approvals, and evidence. Set this boundary carefully before connecting production systems.

Create or join an organization

After signing in, choose the path that matches your situation:

  • Create an organization for a new team. Use a recognizable company or business-unit name and keep visibility private unless there is a specific reason to make it public.
  • Accept an invitation from the email address that received it.
  • Request access with the organization ID when an administrator has asked you to join that way.

An access request stays pending until an administrator approves it. The organization ID identifies a workspace; it does not grant access by itself.

Confirm the active workspace

If you belong to more than one organization, launch the one you intend to work in before you:

  • create or revoke an API key;
  • register an agent or MCP server;
  • change a policy or runtime control; or
  • review approvals and evidence.

The active organization should match the application, environment, and team you are about to configure.

Assign clear ownership

Open Team to invite members and review access. A practical starting model is:

ResponsibilityTypical access need
Organization ownerMembership, billing, and administrative continuity
Security administratorAPI keys, policy, sensitive controls, and evidence access
Operator or reviewerApproval queue, operational events, and incident workflows
DeveloperIntegration setup and the product views needed to verify it

Use the least-privilege role that supports each person's job. Keep at least two trusted administrators so access does not depend on one account.

Prepare for the first integration

Before generating a credential, agree on:

  1. the first application and environment to connect;
  2. the owner who will respond if it fails;
  3. the low-risk action used for the first test;
  4. who may review an action if policy pauses it; and
  5. where the API key will be stored and rotated.

Workspace readiness checklist

  • The intended organization is active.
  • Membership and reviewer access are correct.
  • The first integration has a named owner.
  • A secret manager is ready for the one-time API key reveal.
  • The first action is low risk and reversible or read-only.
  • Everyone knows where to verify the decision and downstream result.

Next step

Continue with Govern your first action, or read Authentication and API keys if your security team needs the credential lifecycle first.