SISuperintelligenceDocs

Search docs

Search every page of the documentation.

Identity and access

Organizations, invites and teams

Manage who belongs to an organization, with which role, and group them into teams.

Open https://id.gov.vin and select an organization. The Members and Teams tabs are visible to every member; owners and admins also see Keys and pending invites.

Organizations

There are two kinds:

  • Customer organizations hold your projects and everything else you build. The platform team creates them (Admin → Organizations → New organization) and invites their first owner. Each has a unique slug, used in URLs.
  • The platform organization runs Superintelligence itself. Its owners and admins also hold the platform scopes and see the Admin app.

Organization settings in Cloud

Cloud → Settings → General:

  • Organization name (needs org:write): shown in Cloud and in invitations; open sessions pick it up as they refresh.
  • Organization slug: used in Cloud, Git and production URLs, so it can't be changed.
  • Organization ID: the id the API uses, and the si:org tag on the organization's AWS resources.
  • Delete organization: owners only, and only for customer organizations that are empty. Remove its projects, repositories, databases, buckets, connectors, active agents and knowledge pages first; Cloud lists what's left. Members, teams, invitations and keys are deleted with it. Can't be undone.

Settings → Members shows members and teams read-only; invitations, roles and teams are managed here in the identity app. Settings → Usage shows what the organization has in use.

Members

The Members tab lists everyone with their role. A member's role comes from the invite they accepted. See Roles and scopes for what each role can do.

Invite someone

Owners and admins invite from Members: enter an email address, choose a role and select Invite. Only owners can invite owners.

  • In production the invite is emailed from noreply@id.gov.vin. Where email isn't sent, the page shows the link to share instead.
  • The link works for 7 days and can be used once.
  • Pending invites are listed with Revoke invite.

The person accepts by creating an account with that email address, or by signing in to the account that has it. See Accounts and organizations.

Teams

Teams group members within an organization.

  • Create: owners and admins enter a name and a slug (2–40 lowercase letters, numbers and dashes). The creator becomes the team's maintainer.
  • Members: owners, admins and the team's maintainers add members of the organization and remove them.
  • Delete: owners and admins.

Team access

Owners and admins can give a team write access to a project or a repository, under the team on the organization's page at https://id.gov.vin. Members of the team then can do what a developer can with that project (deploy, change settings and environment variables) or repository (push from the web, branches, pull requests), whatever their organization role. Access adds to the role and never takes anything away; everything else still follows the role. Changes reach someone's session within 15 minutes, and are recorded in the audit log (team.grant_add, team.grant_remove).

Invites, joins, team changes and keys are recorded in the audit log.