Organizations and access
Organize security work, invite collaborators, and control shared access.
After first-time setup has established an administrator, organizations provide shared workspaces for scans, registries, policies, tokens, notifications, status pages, and audit history. Create an organization before configuring a team-owned registry or delivery gate so evidence and ownership survive individual role changes.
Invite members from the organization page and assign the least privileged role that lets them complete their work. Use organization ownership for the resources that must be maintained by a team; personal workspaces remain appropriate for individual experiments.
Organization tokens are designed for automation. Give CI tokens only the required scopes, store them in the CI secret manager, and revoke a token immediately when it is exposed or no longer needed.
Personal resources can be transferred to another owner or shared with an organization when teams need continuity without recreating scan history. Review resource ownership during team changes and keep the former owner from being the only administrator or token owner.
See identity, roles, and automation access for the identity and token lifecycle, and audit and governance for review practices.