Access & policy
End-user documentation never describes “flip a switch because you are platform admin” for org mutations.
Privilege boundary
| Action | Who can do it |
|---|---|
| View org settings | Org members (some tabs read-only) |
| Change SSO, security, domains | Org admin or owner |
| Invite / remove members | Org admin or owner |
| Transfer ownership | Org owner only |
| Delete organization | Org owner only |
| View any org (read-only) | Platform support (system_admin) — no write bypass |
Ownership transfer
- Only the owner sees Transfer ownership.
- Choose the successor (must already be an org member).
- Confirm by typing the organization name.
- Effects:
- Successor becomes org owner
- Successor becomes owner on every workspace in the org
- Previous owner becomes workspace admin (not owner)
Plan transfers carefully — this is irreversible without another transfer.
SSO safety
| Practice | Why |
|---|---|
| Verify domains before restricting email | Prevents locking out legitimate users |
| Test SSO in a private window | Catches misconfigured redirect URIs |
| Keep one break-glass admin password path until SSO proven | Avoid lockout |
| Review Pending approval regularly | Stale requests block new teammates |
MFA policy
When Require MFA is on:
- Members must enroll in Account → Security before product pages unlock.
- API tokens still work for automation — protect tokens separately.
Invitations
- Send invites only to work emails you trust.
- Revoke unused invites from the Invitations tab.
- Invite links are secrets — treat like password reset links.
Audit & export
- Export audit CSV only to approved storage.
- Redact or avoid sharing exports with unrelated third parties.