Organizations and teams
Tenancy is a four-level hierarchy. Budgets, rate limits, and many portal views roll up along it. Managed cost-center attribution is assigned alongside this hierarchy but follows its own precedence.
Organization
The top-level tenant. Platform admins create orgs and assign ORG_ADMIN / ORG_MEMBER. An org budget caps every team beneath it. The organization switcher in the top bar narrows pages such as the Dashboard, FinOps Analytics, Request Logs and API Keys to one org (see Navigating the portal).
Team
A team sits inside an org. Team admins (TEAM_ADMIN) review key requests, manage members and applications, and operate team keys. Org admins are treated as team admin for every team in the org.
Create teams from the Teams page (org admin or platform admin).
Application
Optional grouping under a team (for example internal-chat or an
environment). Applications can have their own budget and can be blocked —
which blocks their keys.
An application can also have a direct managed cost center. For request attribution, the precedence is Application → Team → Organization → User. The first direct assignment wins.
Users
Users hold a platform role and optional org/team memberships. The platform is invite-only: a platform admin invites an email with role, org and team already assigned; the account activates on first sign-in.
Membership controls administrative and portal access. Request attribution comes from the virtual key's recorded owner and tenant relationships; a person merely belonging to another team does not move that request into the other team.
See FinOps relationship and data flow for how this hierarchy combines with customers, tags, agents, budgets, SpendLog, and chargeback.