Organizations

An organization is the top-level entity in your evroc account. It represents your company or team and provides a unified structure for managing all your cloud resources, users, and access policies.

What an organization contains

Your organization is the root container for:

  • Projects - Isolated containers for cloud resources
  • Users - People who can access resources within the organization
  • Role bindings - Access grants that link users and service accounts to roles

All resources you create exist within a project, and all projects exist within your organization.

Organization administrators

Organization administrators manage organization-level IAM operations. They can:

  • Create and delete projects
  • Grant and revoke permissions for any user
  • Manage billing and account settings

Organization roles don't grant access to compute, storage, networking, or other resources inside projects. Grant project roles for access to project resources.

Users management

Administrators can invite other users into their organizations, and can remove their access. Users who accept an invitation become members of the organization. In order to grant roles to users and manage their permissions, they must be members of the organization.

Organization model

Each evroc account could belong to multiple organizations. If you need to separate workloads completely (for example, between different business units with separate billing), use separate evroc organizations.

Within a single organization, use projects to isolate resources and control access.