Skip to main content

Organization Security

Organization security combines authorization with policy guardrails. A valid role grant never bypasses a stricter organization policy.

Organization security and policy controls

Who Should Use This Page

Organization owners and security administrators should manage these settings from Organization -> Security.

Configure A Guardrail

Available policies can govern guest access, verified invitation domains, privileged MFA, secret access, coding-agent access, sessions, production approvals, destructive actions, and workspace budgets.

  1. Open the Policies tab.
  2. Select Configure beside a policy.
  3. Set its typed options.
  4. Select Preview impact.
  5. Review the affected people and resources.
  6. Confirm your account and save.

Every update creates a version. Use policy history to restore an earlier known-good version without deleting the record of later changes.

Set Up Multi-Factor Authentication

  1. Open the MFA tab.
  2. Select Set up MFA.
  3. Add the setup key to a standards-compatible authenticator.
  4. Enter the current code.
  5. Store the one-time recovery codes securely.

When privileged MFA policy applies to your role, protected actions remain blocked until enrollment and a current challenge succeed.

Review And Revoke Sessions

The Sessions tab shows organization sessions, authentication method, trusted public network address when available, recent activity, and revocation state. Revoke a lost, shared, or obsolete session from a separate trusted session.

Revocation also prevents the session from issuing new terminal, realtime, or confirmation credentials.

Review Audit History

The Audit tab records governance and security events with actor, resource, decision reason, request identifier, and time. Authorized security staff can export a filtered, secret-safe CSV.

Audit records are integrity-linked and immutable. They never intentionally include passwords, tokens, connection strings, payment details, or secret values.

Automation Identities

Use one automation identity per trusted integration.

  1. Open the Automation tab.
  2. Create an identity with a clear purpose.
  3. Create a credential and store it when shown; it cannot be revealed again.
  4. Grant the identity a narrow role and scope from Access.
  5. Revoke the grant or credential when no longer needed.

Automation identities cannot use human account endpoints and do not receive access merely by being created.

Expected Result

Sensitive changes require the correct permission, recent confirmation, and MFA or approval when policy requires them. Audit history remains available to authorized reviewers.

Troubleshooting

SymptomWhat to check
Protected action requests MFAComplete enrollment or enter a current authenticator/recovery code.
Policy cannot be savedRun impact preview first and correct invalid values.
Session address is unavailableOlder or provider-created sessions may predate trusted public-address capture.
Automation credential is lostRevoke it and create a replacement; stored values cannot be revealed.

Next: Configure enterprise identity or run an access review.