Organizations
Organizations are the Cloud boundary for team access. A person signs in to KB-1 Cloud, belongs to one or more organizations, and enters vaults owned by those organizations.
What an organization controls
Section titled “What an organization controls”- Which users are members.
- Which users are admins.
- Which daemon belongs to the organization.
- Which hosting mode that daemon uses.
- Which vaults members can enter through Cloud.
Vault access is gated by organization membership. A non-member should not get a signed entry assertion for the organization’s vaults.
| Role | Current meaning |
|---|---|
admin |
Can manage organization settings, invitations, member roles, self-hosting keys, and Workspace auto-admit. |
member |
Can enter organization vaults through the authenticated app. |
More detailed per-vault and per-agent permissions can be added later, but the launch model is intentionally simple: organization membership is the main Cloud access boundary.
Agents and organizations
Section titled “Agents and organizations”Agents are safest when their runtime is owned by a responsible human or service account. Add that account to the organization when the workflow requires Cloud entry, then connect the agent through local daemon MCP or Cloud MCP, depending on which surface your deployment has enabled.