Organization Admin Runbooks
These customer runbooks focus on organization access. Never paste invitation links, credentials, secret values, recovery codes, or complete audit exports into support messages.
Compromised Administrator
- Use a separate trusted owner or security-administrator session.
- Suspend the affected membership.
- Revoke the person's organization sessions.
- Revoke automation credentials, identity credentials, grants, delegations, and pending approvals changed during the suspected period.
- Inspect audit history by actor, resource, and time.
- Rotate affected external credentials.
- Run an access review before restoring access.
Stolen Or Misrouted Invitation
- Revoke the invitation from Organization -> People -> Invitations.
- If it may already have been accepted, suspend the resulting membership.
- Revoke that person's sessions.
- Review invitation creation, resend, acceptance, and related audit events.
- Send a replacement only after confirming the intended verified email.
External Partner Offboarding
- Confirm the partner's owned work is transferred.
- Suspend the partner group to stop inherited access immediately.
- Revoke direct grants that do not come from the group.
- Revoke active sessions and automation credentials.
- Remove members or let approved guest expiry complete.
- Archive the partner group after the review is complete.
Incorrect Grant Or Delegation
- Revoke the exact grant or delegation.
- Use Explain access to identify additional direct, group, or inherited sources.
- Confirm an already-open page, terminal, or direct API request no longer succeeds.
- Review actions taken while access was active.
- Create a narrower replacement only after the scope and role are verified.
Identity Provider Outage
- Keep at least one verified local organization owner available.
- Disable the affected connection if discovery or health is unsafe.
- Restore the last known-good public metadata and credential configuration.
- Verify local owner access, provider health, MFA policy, and directory token state.
- Re-enable federated sign-in only after a controlled test succeeds.
Ownership Recovery
Moltern prevents normal removal of the final active owner. If no owner can authenticate, contact Moltern support with the organization name, verified company domain, incident reference, and an authorized company contact. The recovery workflow requires two separate platform operators and creates customer-visible audit evidence.
Budget Incident
- Open Organization -> Budgets and Billing.
- Verify that the latest measurements are current.
- Identify the workspace and workload responsible for the increase.
- Adjust a PAYG cap, budget, or workload capacity only with the appropriate owner.
- Do not delete running data solely to clear an alert.
- Export the bounded usage record for finance review.
Escalation Information
Include the organization, workspace, approximate time, visible error, and request identifier. Do not include passwords, tokens, private keys, connection strings, or secret values.
Related: Organization security, roles and scoped access, and troubleshooting.