The company layer: many teams, one bill, one policy.
What an organization adds
An organization sits above teams and centralizes what companies need centralized:
| Concern | Without an org | With an org |
|---|---|---|
| Billing | Each team pays for itself | One org balance pays for every team |
| Governance | Each team sets its own usage policy | One org policy governs all teams (teams can't widen it) |
| Accounts | Everyone self-registers | Org admins provision managed accounts |
| Visibility | Team or public | An extra org level: visible to every org team, invisible outside |
Teams keep their own members, roles, namespaces, and resources — departments map to teams and keep their isolation.
Creating an organization
The owner of a non-personal team creates the organization from settings → organization. The current team joins it automatically and the creator becomes the first org admin.
Org admins
Org admins are a grant list, not a role inside any team. They manage the organization's teams, people, billing, and usage policy from the organization tab in settings. Adding an admin takes their email; the last admin can't be removed.
Teams in an organization
Org admins get teams into the organization two ways:
- Create a team from the organization page — it's born inside the org, billed by it, and governed by its policy from the first moment. This is also the path for admins who are themselves managed accounts.
- Attach an existing standalone team — this requires both an org admin and that team's owner (org admins can't annex teams they don't own). Attaching stamps the team's existing resources into the org so they can be shared org-wide.
Detaching a team is the reverse and is a custody transfer: the org stops billing it, stops governing it, and loses org-level visibility into it — the team leaves with its work. Org admins only, and the action is audited.
Managed accounts
Org admins can provision accounts for their people (enterprise-managed users). Managed accounts:
- land directly in an org team, with no personal team
- sign in with email link or code like everyone else
- cannot create teams or organizations of their own
- are deactivated and reactivated by org admins, not deleted by the user
This keeps every account, and everything it produces, inside the organization's perimeter.
Billing
An organization has one billing account that pays for all its teams. Org admins see and manage it under settings → organization → billing; members of org teams see that billing is handled by the organization, plus their own team's usage. Team-level plans and payment methods don't apply to org teams.