Skip to content

Organizations and access

Foundation available

One Katra installation belongs to one operating business. That business can represent its own work and client organizations without turning every client into an independent installation operator.

  • One installation has exactly one operating-business organization.
  • Internal users belong to the operating organization.
  • Client organizations provide durable ownership and communication boundaries.
  • Client users receive only explicitly exposed communication, review, and meeting capabilities.
  • Organization membership does not automatically grant Product, Project, repository, or workflow access.

The initial global administrator has installation-wide authority. Organization role changes cannot erase this global authority. Other permissions are evaluated inside an explicit organization scope and fail closed when that scope is missing or malformed.

Authorized administrators can issue seven-day, single-use invitations for accepted organization-scoped roles. Resending invalidates the prior invitation. Invitations can be inspected and revoked, and a self-hosted installation receives the acceptance URL even when mail delivery is unavailable.

The trusted local environment currently permits registration, login, logout, remember-me sessions, and password validation. Email verification, password recovery, passkeys, two-factor authentication, session inventory, and remote session revocation remain deferred.

A future installer must create the first administrator and operating organization, then establish invitation-only enrollment before Katra is exposed to an untrusted network.