Set up your workspace and team
An organization is the shared workspace for your people, policies, credentials, inventory, approvals, and evidence. Set this boundary carefully before connecting production systems.
Create or join an organization
After signing in, choose the path that matches your situation:
- Create an organization for a new team. Use a recognizable company or business-unit name and keep visibility private unless there is a specific reason to make it public.
- Accept an invitation from the email address that received it.
- Request access with the organization ID when an administrator has asked you to join that way.
An access request stays pending until an administrator approves it. The organization ID identifies a workspace; it does not grant access by itself.
Confirm the active workspace
If you belong to more than one organization, launch the one you intend to work in before you:
- create or revoke an API key;
- register an agent or MCP server;
- change a policy or runtime control; or
- review approvals and evidence.
The active organization should match the application, environment, and team you are about to configure.
Assign clear ownership
Open Team to invite members and review access. A practical starting model is:
| Responsibility | Typical access need |
|---|---|
| Organization owner | Membership, billing, and administrative continuity |
| Security administrator | API keys, policy, sensitive controls, and evidence access |
| Operator or reviewer | Approval queue, operational events, and incident workflows |
| Developer | Integration setup and the product views needed to verify it |
Use the least-privilege role that supports each person's job. Keep at least two trusted administrators so access does not depend on one account.
Prepare for the first integration
Before generating a credential, agree on:
- the first application and environment to connect;
- the owner who will respond if it fails;
- the low-risk action used for the first test;
- who may review an action if policy pauses it; and
- where the API key will be stored and rotated.
Workspace readiness checklist
- The intended organization is active.
- Membership and reviewer access are correct.
- The first integration has a named owner.
- A secret manager is ready for the one-time API key reveal.
- The first action is low risk and reversible or read-only.
- Everyone knows where to verify the decision and downstream result.
Next step
Continue with Govern your first action, or read Authentication and API keys if your security team needs the credential lifecycle first.