kestrel-one

Organizations, roles, and access

Understand who owns Kestrel One work and why access can differ between an organization, Project, and shared link.

Kestrel Oneintermediate0.7.0 Stable
Verified 2026-07-13View sourceReport a docs issue

An organization is the top-level home for people, Projects, Knowledge, model access, and administrative policy. Project membership can narrow access further inside that organization.

How access is decided

Kestrel One checks the signed-in person and active organization before returning a Project, Thread, message, file, artifact, Knowledge result, or model deployment. Being an organization member does not automatically make someone a member of every private Project.

Common access paths

  • Organization roles control organization-wide administration and shared resources.
  • Project roles control who may view or change a specific Project and its Threads.
  • Personal API keys represent their owner and remain subject to organization and Project access.
  • Public share links expose only the approved read-only representation identified by that link.

If someone receives an access-denied message, confirm the active organization and Project membership before changing broader roles.