Organization structure
The organization holds billing, members, and optional BYOK credentials (your own AI-model keys); each workspace inside it keeps its own isolated agents, connections, and knowledge bases.Organization settings
Navigate to Admin Settings from the user menu in the top-right corner. The Admin Settings sidebar provides access to all organization management pages:Admin Settings is only visible to organization Owners and Admins, and only they can edit organization settings.
Organization members
Invite team members to collaborate within your organization. Members can be assigned to specific workspaces with role-based access control.Invite members
1
Open organization settings
Go to Admin Settings → Organization and scroll to the Members section.
2
Click Invite Members
Click the Invite Members button in the members section.
3
Enter email addresses
Add one or more email addresses (up to 10 at a time).
4
Select a role
Choose the organization role for the invitees.
5
Assign workspaces and send
Optionally select which workspaces the new members should access, then click Send Invites.Success state: the invitees appear in the members list as pending until they accept the emailed invitation.
Organization roles
Manage members
When editing workspace access for Developers or Viewers, you can also set a role override per workspace — Admin, Developer, or Viewer. This lets an organization Viewer act as a Developer in one workspace, or a Developer act as an Admin where needed.
Subscription and billing
Organization Owners manage the subscription from Admin Settings → Billing: current plan and billing cycle, payment method, upgrades and downgrades, plus usage tracking for credits (the currency agent work consumes), members, and workspaces across the organization. Plans use per-seat billing — each seat grants a credit allocation and allows one active member, and you can pre-purchase seats to grow the credit pool before adding people. Only active members count toward seat usage; pending invitations do not consume seats. See Pricing & Plans for per-plan seat ranges and credit allocations.BYOK
BYOK (Bring Your Own Key) lets an organization use its own AWS Bedrock credentials for the AI-model (LLM) calls behind every agent response, instead of CloudThinker’s shared pool. LLM usage then bypasses the credit system, limited only by your AWS quota, and the data sent to the model stays in your AWS account. Owners configure BYOK at the organization level, and it applies to all workspaces.Best practices
Follow least privilege when assigning roles:- Assign Owner sparingly (1–2 people) and use Admin for team leads who manage workspaces.
- Make most team members Developers, and use Viewer for stakeholders who only need visibility.
- Explicitly assign Developers and Viewers to relevant workspaces, using role overrides for fine-grained control.
- Review access regularly for compliance.
Next steps
Create workspaces
Set up workspaces for your teams and projects
Configure agents
Set up AI agents for your cloud operations