> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloudthinker.io/llms.txt
> Use this file to discover all available pages before exploring further.

# How CloudThinker Fits Together

> See how organizations, workspaces, connections, agents, guardrails, and modules fit together before you set anything up.

CloudThinker has a small number of building blocks: an organization holds workspaces, and each workspace holds the connections, agents, guardrails, and context its modules run on. This page shows how they fit, and links to each one.

## The model at a glance

<img src="https://mintcdn.com/cloudthinker/NIxCc9edTN0oNeiT/images/platform/platform-model-light.svg?fit=max&auto=format&n=NIxCc9edTN0oNeiT&q=85&s=4c4cae2d8bd7dc3b10b8781a0ee41277" alt="CloudThinker model: an organization holds workspaces; each workspace has connections, agents, guardrails, and context that power the four modules, with results in Home, Investigation, and Artifacts" className="block dark:hidden" style={{width: '100%'}} width="960" height="624" data-path="images/platform/platform-model-light.svg" />

<img src="https://mintcdn.com/cloudthinker/NIxCc9edTN0oNeiT/images/platform/platform-model-dark.svg?fit=max&auto=format&n=NIxCc9edTN0oNeiT&q=85&s=e859f243d62dcf5f2dbfcb05e37d5be9" alt="CloudThinker model: an organization holds workspaces; each workspace has connections, agents, guardrails, and context that power the four modules, with results in Home, Investigation, and Artifacts" className="hidden dark:block" style={{width: '100%'}} width="960" height="624" data-path="images/platform/platform-model-dark.svg" />

## Organization and workspaces

Your [organization](/guide/organization) is the account: it owns billing, the plan, and the member list. A [workspace](/guide/workspaces) is an isolated environment inside it — production and staging, or one per team.

| Lives in the organization | Lives in each workspace |
| - | - |
| Billing, plan, and credits | Connections and credentials |
| Members and org roles: Owner, Admin, Developer, Viewer | Custom agents |
| Single sign-on and audit logs | Memory, knowledge bases, and skills |
| | Automations, commands, and approval settings |

Org Owners and Admins are Admins in every workspace. Everyone else gets a workspace role — Admin, Developer, or Viewer — per workspace. See [Workspace users](/guide/workspace-users).

## Connections

A [connection](/guide/connections/overview) is a credential for one service — an AWS account, a Kubernetes cluster, a GitHub organization, a Datadog account. Agents can only see and act on what the workspace's connections allow, so the connection's permissions are the outer limit of what any agent can do.

## Agents

**CloudThinker**, the built-in assistant, takes every request. It spawns temporary subagents for parallel work and hands off to custom agents your team defines. See [Agents](/guide/agents/overview).

## Guardrails

Two settings decide whether an agent's write action runs on its own or waits for a person.

| Setting | What it does | Where |
| - | - | - |
| **Auto** (default for new workspaces) | Write actions are checked by an AI safety classifier before they run | **Approval** control in the chat box |
| **Manual** | You approve each write action before it runs | **Approval** control in the chat box |
| **Tool Permissions** | In Manual, set each connection tool to **Always allow**, **Needs approval**, or **Never allow** | **Settings → Approval → Tool Permissions** |

The mode applies to the whole workspace, including automations and subagents. See [Auto Mode](/guide/auto-mode) and [Approval](/guide/approval).

## Context

Context is what agents know before you say anything. Each kind has a different source.

| Context | What it holds | Who adds it |
| - | - | - |
| [Memory](/guide/memory) | Notes about your environment, preferences, and recent events | Agents, as they work; you can correct it |
| [Knowledge](/guide/knowledge) | Your runbooks, policies, and documentation | You, by uploading files or crawling sites |
| [Skills](/guide/skills/overview) | Step-by-step instructions for a specific kind of task | You, or agents when skill learning is on |

## Modules

The four [modules](/guide/modules) — Resolve, Review, Optimize, and Cyber — each apply the same agents, guardrails, and context to one kind of signal: incidents, pull requests, cloud bills, and app security.

## Where results appear

| Place | What you find there |
| - | - |
| [Home](/guide/activity) | **Needs you** — approvals and decisions waiting on you — plus module status and today's automations |
| **Investigation** (under Resolve) | Every incident, its root cause, evidence, and proposed fix |
| [Artifacts](/guide/artifacts/overview) | Dashboards, reports, and files agents built for you |
| The chat side panel | Runs, console output, subagents, and findings for the current conversation |

## Related

<CardGroup cols={2}>
  <Card title="Agents" icon="robot" href="/guide/agents/overview">
    Learn how CloudThinker, subagents, and custom agents share the work
  </Card>

  <Card title="Modules" icon="table-cells-large" href="/guide/modules">
    Compare what each module does and what it needs
  </Card>

  <Card title="Workspaces" icon="layer-group" href="/guide/workspaces">
    Create and organize isolated environments
  </Card>

  <Card title="Quickstart" icon="bolt" href="/quickstart">
    Put the model to work in about 10 minutes
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.