Skip to main content
Every account works inside an organization, and your personal account counts as one. An org is where machines are billed, where sharing happens, and where secrets live. This page is about the org itself: its members, their roles, and the teams inside it. For what sharing does to a machine, see VM sharing. Everything here is available from the console’s Organization page, from boxd auth org and boxd teams on the CLI, and from the SDKs’ orgs and teams namespaces.

Roles

Create an org and manage its roster

A few rules keep the org safe from its own credentials:
  • Invites carry a role. The invitee lands as member or admin, and an admin invite can only be sent from an interactive login. An API key or a token minted inside a machine cannot send one, and cannot read the links of pending invites either. It still sees that an invite is pending.
  • Demoting another admin is owner-only. An admin can always demote themselves.
  • The owner’s role cannot be changed with set-role, and an owner or admin cannot be removed with remove-member. Both go through the boxd team.
  • A member who still owns org-billed machines cannot be removed. Move those machines to personal billing or destroy them first.
Every one of these commands follows the active org context, so boxd auth switch acme first, or pass --org acme for one call.

Teams

A team is a group of members inside an org, with an optional default snapshot. A machine created by a team member boots from that snapshot unless they pick another one, which is how a team hands every new machine the same starting point. See Golden image.
An org admin has team-admin authority on every team. A team admin has it on their own team.

From the SDKs

See Organizations and Teams in the Python reference, and the same sections in the TypeScript reference.

Live everywhere

A change made on one surface shows up on the others without a reload. Invite someone from the CLI and the console’s Organization page lists the invite as it lands. The same goes for role changes, team rosters, and every machine setting.