Skip to main content

Organizations (tenants)

Everything in Orca lives inside an organization, your tenant. Agents, profiles, secrets, keys, runs, and usage all belong to one organization, and data is isolated per tenant: one organization can never see or reach another’s data. The tenant is always derived from your credential: an API key carries its tenant, and a dashboard session carries yours. (Orca strips any X-Tenant-ID header, so the tenant can’t be spoofed by a request.)

Roles (RBAC)

Orca’s RBAC recognizes four role tiers, but the standard product flow (the dashboard invite dialog, and Clerk’s default organization roles) only assigns two of them, admin and member. owner and viewer exist as forward-compatible tiers for custom Clerk roles and are not assignable through the standard flow today.

Admin-only surfaces

These actions require admin (or owner):
  • Managing Secrets (create, rotate, delete). Unlike other admin-only surfaces, Secrets has no read-only affordance for members: the dashboard shows a locked “Admin only” state and never queries the list, and the API returns 403 to members on reads too, not just writes.
  • Publishing an agent.
  • Deleting an agent.
  • Editing the monthly spend cap.
  • Changing notification settings.
  • Creating, editing, deleting, or republishing workflow templates.
  • Deleting a pod.
  • Organization management: rename, logo, delete, and inviting or removing members.
Starting a paid billing checkout requires the owner role specifically, stricter than the rest of this list. Members see read-only versions of most of these surfaces rather than the controls; Secrets is the exception above.

API keys inherit their creator’s role

An API key takes on the role of whoever created it. A key issued by an admin can reach admin-only surfaces; a key issued by a member is limited to member-level actions. Choose the issuing account deliberately to scope a key. Visibility of keys themselves is also role-scoped: a member can only see and manage the tenant API keys they personally created, while an admin or owner can see and manage every key in the tenant regardless of who created it.

Managing the organization

Organization lifecycle and membership are managed in the dashboard under Organization and Members, where you rename the org, set its logo, and invite or remove people.

API Keys

Keys inherit their creator’s role.

Secrets

An admin-only surface.
Last modified on September 6, 2026