Organizations (tenants)
Everything in Orca lives inside an organization, your tenant. Agents, profiles, secrets, keys, runs, and usage all belong to one organization, and data is isolated per tenant: one organization can never see or reach another’s data. The tenant is always derived from your credential: an API key carries its tenant, and a dashboard session carries yours. (Orca strips anyX-Tenant-ID header, so the tenant can’t be spoofed by a request.)
Roles (RBAC)
Orca’s RBAC recognizes four role tiers, but the standard product flow (the dashboard invite dialog, and Clerk’s default organization roles) only assigns two of them, admin and member. owner and viewer exist as forward-compatible tiers for custom Clerk roles and are not assignable through the standard flow today.Admin-only surfaces
These actions requireadmin (or owner):
- Managing Secrets (create, rotate, delete). Unlike other admin-only surfaces, Secrets has no read-only affordance for members: the dashboard shows a locked “Admin only” state and never queries the list, and the API returns 403 to members on reads too, not just writes.
- Publishing an agent.
- Deleting an agent.
- Editing the monthly spend cap.
- Changing notification settings.
- Creating, editing, deleting, or republishing workflow templates.
- Deleting a pod.
- Organization management: rename, logo, delete, and inviting or removing members.
API keys inherit their creator’s role
An API key takes on the role of whoever created it. A key issued by an admin can reach admin-only surfaces; a key issued by a member is limited to member-level actions. Choose the issuing account deliberately to scope a key. Visibility of keys themselves is also role-scoped: a member can only see and manage the tenant API keys they personally created, while an admin or owner can see and manage every key in the tenant regardless of who created it.Managing the organization
Organization lifecycle and membership are managed in the dashboard under Organization and Members, where you rename the org, set its logo, and invite or remove people.Related
API Keys
Keys inherit their creator’s role.
Secrets
An admin-only surface.