Skip to main content
Your organization owns its members, projects, provider connections, policies, and reporting. Use projects to separate applications or environments; use teams to group members and attribute costs. The account menu opens Projects, Users, Teams, and API keys. Manage roles from the Roles tab in Users.

Create another organization

Open Switch organization in the account menu, then choose Create an organization. This works even when you currently belong to a single organization. Enter the new organization’s name and slug, accept the Terms of Service and acknowledge the Privacy Notice, then select Create organization. Complete verification if the form requests it. Aixy uses the account you have already signed in to; you do not need to enter your name, email or password again. You become the new organization’s Owner and enter its default project. Your existing organization’s role and your account credentials stay the same. If you signed in with SSO, you can return to organizations created that way by signing in through the same provider and choosing an organization. Access depends on your membership and the provider remaining active in the original organization. Each organization’s required SSO policy still applies. Manage passwords and passkeys from Account settings inside an organization using personal password or passkey authentication.

Create a project

  1. As an Owner or Org admin, open Projects → Create project.
  2. Enter a name and unique project slug, then save.
  3. Open the project’s access page and assign the members who should use it.
  4. Select the project in the sidebar and configure its providers, models, and controls.
Owners and the initial Org admin role have organization-wide project access. Custom roles can also include all-project access. Project-role users need an explicit project assignment. A key belongs to one project; use separate projects and keys when traffic needs different provider accounts, access, or budgets.

Choose a role

New organizations start with these roles. Owner is protected; the other three can be customized. Analytics access is a separate setting. An administrator can give a project member Personal usage only or Project and personal usage without changing their operational role. Activity permissions independently determine whose individual requests they can inspect.

Customize roles

Open Users from the account menu, then select the Roles tab. Select a role to edit it, or choose Create role. Give it a clear name and describe who should use it.
  • Aixy profiles supply permissions that evolve as Aixy adds features. Project profiles remain within project access and do not acquire organization administration.
  • Individual permissions let you choose each capability. A role with no selected profiles stays exactly as configured; new permissions are added manually.
  • Combine profiles with extra permissions when useful. Inherited permissions are marked From profile. Choose Use individual permissions to detach the profiles and edit every current grant yourself.
The Effective access summary shows project scope, organization access, and how future permissions are handled. Project permissions still require project assignments unless the role includes all-project access. Save changes, then assign the role from a member’s details or an invitation. Existing members receive edits on subsequent dashboard requests. Owner always includes every permission and cannot be edited or deleted. Only Owners can assign ownership or all-project roles. Delegated role administrators cannot grant permissions they do not hold or edit their own role. Keep at least one active Owner. SSO defaults, team defaults, and project invitation links accept custom roles with project-only permissions. Such roles cannot acquire organization administration while those references exist. Only unused custom roles can be deleted; initial roles remain available for editing. Retained invitation references also prevent deletion. Role edits change dashboard and MCP authorization. They do not revoke existing model API keys; revoke keys or suspend a member when removing their ability to send model traffic.

Invite and manage members

Open Users to invite a member by email, choose their role, and assign projects. The Members and Invitations views separate accepted accounts from pending access. You can also create a shareable project invitation link for new members, choosing a project role and link lifetime. Treat that link as a credential: anyone with a valid link can use its invitation permissions. Opening an invitation shows the organization, role and assigned projects. If you are signed in, choose Accept invitation to join with your existing account; you do not enter your name, email or password or repeat the signup Terms acknowledgement. An email invitation must match your account. Choose Use another account if the invitation is for a different email. If you are signed out, the invitation keeps the existing signup form. For an existing member, edit project access from the user or project’s access page. Removing a project assignment revokes keys tied to that removed access. Resending an email invitation replaces its previous secret; revoke invitations that should no longer grant access.

Use teams for organization and cost attribution

Create a team in Teams, then assign members. When creating an API key, select its Team cost center to attribute traffic to that team. Team membership alone does not assign project access; manage the member’s project assignments separately. Use budgets for a shared team cost limit, or an organization/project allocation for each user. Traffic belongs to the key’s recorded owner, so give developers individual keys when you need personal attribution.

Suspend or remove access

Suspend a user to stop sign-in and revoke existing sessions, project keys, and MCP tokens while retaining memberships and resource authorship. Reactivation allows a fresh sign-in and new credentials; previously revoked secrets remain revoked. Keep at least one active Owner. For centralized sign-in, configure Google Workspace SSO. For workload credentials, follow API key management.

Request your account data

Open Account settings → Your personal data and select Request a copy. Aixy prepares the available records for your account in the current organization. Return to the page to download the JSON file; it expires after seven days and is accessible only while signed in to that account. The file identifies included records and omissions. A partial copy does not include customer content, business correspondence or every record held by external services. Follow the contact path in the dashboard’s Privacy Notice for a broader request. Removing an Aixy account also does not delete an account at your organization’s identity provider.