> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aixy-gateway.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Organization and access

> Organize projects, invite members, and assign responsibility.

Your organization owns its members, projects, provider connections, policies, and reporting.
Use projects to separate applications or environments; use teams to group members and attribute
costs. The account menu opens **Projects**, **Users**, **Teams**, and **API keys**. Manage roles
from the **Roles** tab in **Users**.

## Create another organization

Open **Switch organization** in the account menu, then choose **Create an organization**.
This works even when you currently belong to a single organization. Enter the new organization's
name and slug, accept the Terms of Service and acknowledge the Privacy Notice, then select
**Create organization**. Complete verification if the form requests it.

Aixy uses the account you have already signed in to; you do not need to enter your name, email or
password again. You become the new organization's Owner and enter its default project. Your
existing organization's role and your account credentials stay the same.

If you signed in with SSO, you can return to organizations created that way by signing in through
the same provider and choosing an organization. Access depends on your membership and the provider
remaining active in the original organization. Each organization's required SSO policy still applies.
Manage passwords and passkeys from **Account settings** inside an organization using personal
password or passkey authentication.

## Create a project

1. As an Owner or Org admin, open **Projects → Create project**.
2. Enter a name and unique project slug, then save.
3. Open the project's access page and assign the members who should use it.
4. Select the project in the sidebar and configure its providers, models, and controls.

Owners and the initial Org admin role have organization-wide project access. Custom roles can
also include all-project access. Project-role users need an explicit
project assignment. A key belongs to one project; use separate projects and keys when traffic
needs different provider accounts, access, or budgets.

## Choose a role

New organizations start with these roles. Owner is protected; the other three can be customized.

| Role | Responsibility |
| - | - |
| Owner | Organization administration, billing, protected role assignment, and all projects |
| Org admin | Organization operations and all projects, excluding billing and management of Owner/Org admin accounts |
| Project admin | Configuration and operations within assigned projects |
| Project user | Approved models, personal project keys, Playground, and their own request Activity |

Analytics access is a separate setting. An administrator can give a project member **Personal
usage only** or **Project and personal usage** without changing their operational role. Activity
permissions independently determine whose individual requests they can inspect.

## Customize roles

Open **Users** from the account menu, then select the **Roles** tab. Select a role to edit it,
or choose **Create role**. Give it a clear name and describe who should use it.

* **Aixy profiles** supply permissions that evolve as Aixy adds features. Project profiles remain
  within project access and do not acquire organization administration.
* **Individual permissions** let you choose each capability. A role with no selected profiles
  stays exactly as configured; new permissions are added manually.
* Combine profiles with extra permissions when useful. Inherited permissions are marked
  **From profile**. Choose **Use individual permissions** to detach the profiles and edit every
  current grant yourself.

The **Effective access** summary shows project scope, organization access, and how future
permissions are handled. Project permissions still require project assignments unless the role
includes all-project access. Save changes, then assign the role from a member's details or an
invitation. Existing members receive edits on subsequent dashboard requests.

**Owner** always includes every permission and cannot be edited or deleted. Only Owners can
assign ownership or all-project roles. Delegated role administrators cannot grant permissions they
do not hold or edit their own role. Keep at least one active Owner.

SSO defaults, team defaults, and project invitation links accept custom roles with project-only
permissions. Such roles cannot acquire organization administration while those references exist.
Only unused custom roles can be deleted; initial roles remain available for editing. Retained
invitation references also prevent deletion.

Role edits change dashboard and MCP authorization. They do not revoke existing model API keys;
revoke keys or suspend a member when removing their ability to send model traffic.

## Invite and manage members

Open **Users** to invite a member by email, choose their role, and assign projects. The **Members**
and **Invitations** views separate accepted accounts from pending access. You can also create a
shareable project invitation link for new members, choosing a project role and link lifetime.
Treat that link as a credential: anyone with a valid link can use its invitation permissions.

Opening an invitation shows the organization, role and assigned projects. If you are signed in,
choose **Accept invitation** to join with your existing account; you do not enter your name, email
or password or repeat the signup Terms acknowledgement. An email invitation must match your account.
Choose **Use another account** if the invitation is for a different email. If you are signed out,
the invitation keeps the existing signup form.

For an existing member, edit project access from the user or project's access page. Removing a
project assignment revokes keys tied to that removed access. Resending an email invitation replaces
its previous secret; revoke invitations that should no longer grant access.

## Use teams for organization and cost attribution

Create a team in **Teams**, then assign members. When creating an API key, select its **Team cost
center** to attribute traffic to that team. Team membership alone does not assign project access;
manage the member's project assignments separately.

Use [budgets](/costs/budgets) for a shared team cost limit, or an organization/project allocation
for each user. Traffic belongs to the key's recorded owner, so give developers individual keys
when you need personal attribution.

## Suspend or remove access

Suspend a user to stop sign-in and revoke existing sessions, project keys, and MCP tokens while
retaining memberships and resource authorship. Reactivation allows a fresh sign-in and new
credentials; previously revoked secrets remain revoked.

Keep at least one active Owner. For centralized sign-in, configure
[Google Workspace SSO](/administration/sso). For workload credentials, follow
[API key management](/authentication).

## Request your account data

Open **Account settings → Your personal data** and select **Request a copy**. Aixy prepares the
available records for your account in the current organization. Return to the page to download
the JSON file; it expires after seven days and is accessible only while signed in to that account.

The file identifies included records and omissions. A partial copy does not include customer
content, business correspondence or every record held by external services. Follow the contact
path in the dashboard's Privacy Notice for a broader request. Removing an Aixy account also does
not delete an account at your organization's identity provider.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.