Identity and access

Organizations, invites and teams

Manage who belongs to an organization, with which role, and group them into teams.

Open https://id.cactive.com.au and select an organization. The Members and Groups tabs are visible to every member; owners and admins also see Keys. Owners and admins invite, block and remove people, manage groups, roles, apps and the sign-in policy in Tenant.

Organizations

There are two kinds:

  • Customer organizations hold your Serverless App Services and everything else you build. The platform team creates them (Admin → Organizations → New organization) and invites their first owner. Each has a unique slug, used in URLs.
  • The platform organization runs Cactive itself. Its owners and admins also hold the platform scopes and see the Admin app.

Organization settings in Cloud

Cloud → Settings → General:

  • Organization Name (needs org:write): shown in Cloud and in invitations; open sessions pick it up as they refresh.
  • Organization Slug: used in Cloud, Git and production URLs, so it can't be changed.
  • Organization ID: the id the API uses, and the si:org tag on the organization's AWS resources.
  • Delete Organization: owners only, and only for customer organizations that are empty. Remove its Serverless App Services, repositories, databases, buckets, connectors, active agents, knowledge pages, Drive files, mailboxes and mail domains first; Cloud lists what's left. Members, teams, invitations, keys, shared environment variables and the organization's mail sending settings, suppression list and Apple Mail sign-ins are deleted with it, and leftover build caches, build logs and access roles within a day. Can't be undone.

Settings → Members shows members and groups read-only; invitations, roles and groups are managed in Tenant. Settings → Usage shows what the organization has in use.

Members

The Members tab lists everyone with their role. A member's role comes from the invite they accepted, and owners and admins change it in Tenant; a group can give a higher one. See Roles and scopes for what each role can do.

Invite someone

Owners and admins invite from Tenant → Users → Invite: one address, or many from CSV, with a role, title, department, groups to join, and guest access for people from outside the organization. Only owners can invite owners.

  • In production the invite is emailed from noreply@id.cactive.com.au. Where email isn't sent, Tenant shows the link to share instead.
  • The link works for 7 days (up to 30) and can be used once.
  • Pending invites are listed with Resend and Revoke.

The person accepts by creating an account with that email address, or by signing in to the account that has it. See Accounts and organizations.

Groups (teams)

Groups gather members within an organization; they're the teams of earlier versions.

  • Create and delete: owners and admins, in Tenant → Groups. The creator becomes the group's owner.
  • Members: owners, admins (in Tenant) and the group's owners (here, on the Groups tab) add members of the organization and remove them.
  • A group can also give its members a role, custom roles and app access; see Tenant.

Team access

Owners and admins can give a group write access to a Serverless App Service or a repository, on the group's page in Tenant. Members of the team then can do what a developer can with that Serverless App Service (deploy, change settings and environment variables) or repository (push from the web, branches, pull requests), whatever their organization role. Access adds to the role and never takes anything away; everything else still follows the role. Changes reach someone's session within 15 minutes, and are recorded in the audit log (team.grant_add, team.grant_remove).

Invites, joins, team changes and keys are recorded in the audit log.