Teams
Invite people into the organization that holds the credit, and give them the access their job needs.
An organization owns the credit, the keys and the usage. Signing up provisions one. Everyone else is invited into it.
Roles
| Role | Can |
|---|---|
| Owner | Everything, including billing and removing members |
| Admin | Manage keys and members; not billing |
| Member | Read usage; use existing keys |
Inviting
From Teams, invite by email. The invitation is a link, valid until it is accepted or revoked.
There is no mail transport wired up in development, so the link is logged and shown on the Teams screen instead of being sent. In production it goes to the address.
Keys are shared
An API key belongs to the organization, not to the person who created it. Somebody leaving does not break the service using their key — and equally, removing them does not revoke it. Rotate deliberately rather than assuming offboarding did it for you.
One organization per account, for now. Signup provisions exactly one and there is no picker yet. The data model already supports more, so this is a screen that does not exist rather than a limit that is baked in.