Organizations
Organization vs project boundaries, roles, credentials, and the active org switcher.
Organizations
An organization is the tenant boundary above projects. One ArxDeck deployment serves many customer organizations with isolated access. Projects, tickets, and most settings live inside a project; organizations group projects and shared credentials.
Organization vs project
| Layer | What it owns |
|---|---|
| Organization | Members, org-wide API keys, external MCP server registry, project list |
| Project | Tickets, workflows, agents, knowledge, chat, and project settings |
Every project belongs to exactly one organization. See Projects for project-level roles and content.
Roles
Organization roles
| Role | Access |
|---|---|
| Org admin | Manage org members, invites, credentials, MCP servers, and create/archive projects. Implicit project admin on all active projects in the org — no per-project membership row required. |
| Org member | Must be added to each project explicitly with a project role. |
| Org guest | External read-only collaborator. No implicit project access — only projects with an explicit membership row. On those projects, viewer only. Org admins can invite guests with no project; project-only invites for new users create guest membership. |
Guests cannot access organization settings (members, credentials, deployments, and so on). Demoting a member or admin to guest requires choosing whether to remove their project access or keep it as viewer.
Project roles
| Role | Typical permissions |
|---|---|
| Project admin | Manage members, workflows, agents, integrations, and ticket mutations |
| Member | Create and edit tickets, comments, chat, and knowledge |
| Viewer | Read-only access |
Platform superadmins manage the global catalog (workflows, agents, skills, content modules) and organization lifecycle. They do not get implicit access to every project's data.
Active organization switcher
The sidebar organization switcher sets which org's projects and settings you see. After switching orgs, you return to the dashboard home so navigation stays aligned. Deep links to a project auto-select that project's organization.
Organization hub
Organization admins open Organization in the sidebar (/settings/org). The hub lists compact rows (no category groups):
| Row | Route | Purpose |
|---|---|---|
| Members | /settings/org/members | Invite and manage organization members |
| Projects | /settings/org/projects | Create, archive, and manage projects |
| API keys | /settings/org/credentials | Provider credentials projects inherit |
| MCP servers | /settings/org/mcp | External MCP endpoints agents can call |
| Voice | /settings/org/voice | Organization speech-to-text provider and idle protection |
| Deployments | /settings/org/deployments | Publish limits and budgets |
Detail pages use breadcrumbs instead of horizontal tabs.
Organization credentials
Org admins configure shared secrets at Organization → API keys and Organization → MCP servers:
- API keys — provider credentials projects inherit (organization overrides platform defaults)
- Voice — organization speech-to-text provider (Browser, Deepgram, or AssemblyAI) and idle protection thresholds
- External MCP servers — HTTP MCP endpoints agents can call (static or OAuth)
Resolution order for API keys: organization → platform. Project admins do not store raw secrets in agent JSON — credentials resolve at run time.
Invitations
Organization admins invite members at Organization → Members. Project admins can invite users to specific projects by email, or add an accepted organization member directly from Project → Settings → Members with Add organization member (no email or acceptance step). Users who join through a project invite (and are not already org members) become org guests with viewer-only access on that project. Invitations are emailed to the invitee when mail is configured; admins can resend pending invites or share the link manually. Existing users accept invites by opening the link, signing in with the invited email, and clicking Accept invitation.
Setup & configuration
| Task | Who | Where |
|---|---|---|
| Invite org members | Org admin | Organization → Members |
| Create projects | Org admin | Organization → Projects or dashboard Create project |
| Configure API keys | Org admin | Organization → API keys |
| Register external MCP | Org admin | Organization → MCP servers |
| Add someone to one project | Project admin | Settings → Members |
Related
- Projects
- Integrations overview — org prerequisites for credentials
- MCP integration
- Getting started
