An organization is the top-level home for people, Projects, Knowledge, model access, and administrative policy. Project membership can narrow access further inside that organization.
How access is decided
Kestrel One checks the signed-in person and active organization before returning a Project, Thread, message, file, artifact, Knowledge result, or model deployment. Being an organization member does not automatically make someone a member of every private Project.
Common access paths
- Organization roles control organization-wide administration and shared resources.
- Project roles control who may view or change a specific Project and its Threads.
- Personal API keys represent their owner and remain subject to organization and Project access.
- Public share links expose only the approved read-only representation identified by that link.
If someone receives an access-denied message, confirm the active organization and Project membership before changing broader roles.