Organization workspace

Coordinate people without hiding ownership.

The organization is the tenant and governance boundary. Use Home for personal attention, People and Teams for collaboration, and Access settings for explicit, versioned authorization.

Organization scopeClaim-filtered navigationAudited changes
Every memberHome, authorized content, directory, and personal preferences.
Access managersInvitations, team membership, roles, and scoped assignments.
EvidenceImmutable role versions, assignment history, and audit events.
Orientation

Understand the organization surface

Open an organization from Account home. The visible sidebar is computed from the organization's enabled capabilities and your effective claims; a missing destination usually means the capability is unavailable or your role does not include its required claim.

Home
Your assigned active work, seven-day schedule, requested reviews, delivery attention, and project list.
Inbox
Mentions, assignments, invitations, reviews, and delivery notifications.
People
Directory of current members, roles, and join dates.
Teams
Organization-owned groups with their own overview, work, calendar, chat, and time context.
Projects
Optional delivery spaces for Work, Code, reviews, pipelines, Packages, and project Knowledge.
Search
Authorization-filtered results across projects, work, Knowledge, packages, and code.
No project is required.

You can use News, Chat, Teams, Calendar, Knowledge, People, and Time directly at organization scope.

Personal workflow

Work from Home and Inbox

OrganizationHome
  1. Review assigned work.Home groups your active project work into Open, In progress, and Done lanes.
  2. Move an item when its state changes.Drag it to a lane or use the accessible lane selector. The project workflow transition is saved; failures remain visible on Home.
  3. Scan the next seven days.Upcoming organization and project events appear beside work attention.
  4. Respond to review and delivery attention.Open requested pull-request reviews, failed or running pipelines, and due milestones from their cards.
  5. Clear notifications.Open Inbox, follow the destination, then choose Mark read. Load older items when pagination is available.

Personalize the lanes

OrganizationSettingsHome preferences

Rename, reorder, or hide the three personal Home lanes. These preferences are stored for this account and organization in the current browser; they never modify a project's workflow.

Success state

Home reflects your selected labels and order, while moved work retains its canonical project status.

Workflow 1

Create and maintain a team

Permission

Manage teams is required to create teams or change their membership. Other members can view teams made visible to them.

OrganizationTeamsNew team
  1. Set the identity.Enter a name and URL slug.
  2. Explain the team's purpose.Write a rich description. Later edits preserve immutable description history.
  3. Create the team.Open its detail page and use Overview, Organization work, Calendar, Chat, or Time as needed.
  4. Add existing members.Go to Settings › Access › Teams, choose the team, then Add member. Only organization members not already on the team are offered.
  5. Remove membership carefully.Choose the member and confirm removal. This changes team-derived authorization but does not delete the person's organization membership.

Success state

The member appears in the team's membership list and receives any access derived from that team and its scoped assignments.

Workflow 2

Invite an organization member

Permission

The form requires both Manage members and Manage roles. Adding the invitee to a team also requires Manage teams.

OrganizationSettingsAccessMembersInvite member
  1. Enter the email.The invite must later be accepted by an account with this verified address.
  2. Select the exact role version.Choose a seeded or custom role version. Future edits to the role create another version rather than changing this invitation silently.
  3. Optionally select a team.The invitee joins that team atomically with organization membership.
  4. Issue the invitation.It expires after seven days. Copy the one-time invitation URL from the success receipt before leaving.
  5. Track or revoke it.Pending invitations appear under Members. Revoke one that was sent to the wrong address or is no longer needed.
The URL is a one-time secret.

It cannot be displayed again after you leave the creation route. If it is lost, revoke the invitation and create another.

Workflow 3

Change a member's organization role

OrganizationSettingsAccessMembers
  1. Find the member.Load additional members if the organization is paginated.
  2. Choose the role.Available seeded roles are Owner, Maintainer, Contributor, Auditor, and Billing manager; custom role versions may also be available.
  3. Save against current state.The server verifies the current member version and prevents stale overwrites.
  4. Review effective access.Team membership and scoped assignments can add claims beyond the organization role.

Self-demotion is rejected when it would leave the organization without another authorized administrator. Promote a second suitable member first.

Workflow 4

Create a custom role version

Permission

Manage roles is required.

OrganizationSettingsAccessRolesNew role
  1. Identity.Enter the role name, description, and immutable key.
  2. Permissions.Select the grouped claims included in version 1. Claims are additive; a role cannot deny access granted by another assignment.
  3. Review.Confirm the key and complete claim set, then create the immutable first version.
  4. Revise later.The current editor creates a new version when you change the role name or description and preserves the existing claim set. Existing memberships and invitations continue pointing to their exact assigned version until changed.

Success state

The role appears with version history and can be selected for membership, invitations, or scoped-role assignments.

Workflow 5

Grant scoped role or stewardship

OrganizationSettingsAccessAssignmentsNew assignment
  1. Choose the assignment kind.Use Scoped role for a role version or Resource stewardship for Owner/Maintainer responsibility.
  2. Choose the subject.Assign to one user or a team.
  3. Choose the scope.Select the entire organization, a project, or an exact resource type and UUID.
  4. Review and create.The new authorization is additive and is evaluated with all other membership and team-derived assignments.
  5. Remove when no longer required.Confirm removal from the assignment inventory; the audit record remains.
Evidence

Inspect the audit trail

Permission

The Audit destination appears only to members whose effective claims allow audit-log access.

OrganizationSettingsAccessAudit

Browse immutable events, load older results, and open an event to inspect its structured detail. Use the actor, resource, action, and recorded payload to understand sensitive membership, role, visibility, moderation, and stewardship changes.

Troubleshooting

Empty states, conflicts, and access failures

Access denied or a settings link is absent

Your effective claims do not include the required action, or the organization capability is disabled. Ask an Owner or suitable role manager to review your exact role version and scoped assignments.

No member can be added to a team

Every loaded organization member already belongs to the team. Load more organization members if available, or invite the person to the organization first.

The invitation no longer accepts

It expired, was revoked or consumed, targets another verified email, references a role version no longer accepted by policy, or its optional team is no longer valid. Revoke and issue a fresh invitation after correcting the inputs.

The save reports a conflict

Another authorized person changed the resource after you loaded it. Reload the current member, role, or assignment state and deliberately reapply the intended change.

  • People is a directory, not the place to mutate access.
  • Team removal does not remove organization membership.
  • Role versions and audit events are immutable.
  • Home-lane preferences are browser-local and personal.