> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.co.in/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/docs/_mcp/server.

# Organizations and tenancy model

> Understand organizations, workspaces, ownership boundaries, and how tenancy works in IBEE Solutions.

IBEE Solutions uses a two-level tenancy model: **organizations** contain **workspaces**, and workspaces contain resources. Billing, team management, and access controls live at the organization level, while compute, storage, and networking resources are scoped to individual workspaces.

## Tenancy hierarchy

```
Account (your login)
└── Organization (billing, team, API tokens)
    └── Workspace (VMs, storage, networking, firewalls)
```

* **Account** — your login identity. One account can own or be a member of multiple organizations.
* **Organization** — the billing and administrative boundary. Each organization has its own wallet, payment method, invoices, team members, API tokens, and activity logs.
* **Workspace** — the resource boundary within an organization. VMs, block storage volumes, object storage buckets, firewalls, load balancers, DNS zones, and other infrastructure resources belong to a workspace.

## What lives where

| Level            | What it contains                                                                                                                                                                                                            |
| ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Organization** | Billing (wallet, invoices, payment method, usage limits), team members, API tokens, activity logs, organization settings, KYC/verification status                                                                           |
| **Workspace**    | Cloud VMs, GPU VMs, bare metal servers, object storage buckets, block storage volumes, load balancers, DNS zones, VPCs, firewalls, SSL certificates, backups, snapshots, ISOs, SSH keys, secret manager, container registry |

## URL structure

The portal URL reflects the tenancy model:

| Scope                 | URL pattern                                           | Example              |
| --------------------- | ----------------------------------------------------- | -------------------- |
| Organization home     | `/organizations/{orgId}/workspaces`                   | Workspace listing    |
| Organization settings | `/organizations/{orgId}/settings`                     | Organization details |
| Billing               | `/organizations/{orgId}/billing/summary`              | Billing summary      |
| Team                  | `/organizations/{orgId}/users`                        | Team members         |
| Workspace resource    | `/organizations/{orgId}/workspaces/{wsId}/{resource}` | Cloud VMs list       |

## Creating an organization

See [Create an organization](/docs/getting-started/account-setup/create-an-organization) for the step-by-step process. Each organization requires a name, account type (Business or Individual), billing address, and currency. You can own up to 3 organizations and join up to 20 by default — see [Organization limits](/docs/platform-fundamentals/limits-and-quotas#organization-limits).

To update an organization's name, address, or tax details later, see [Organization settings](/docs/platform-fundamentals/organization-settings).

## Switching organizations

Use the **organization switcher** dropdown in the top navigation bar to move between organizations. You can also return to the Organizations page and select a different card.

## Workspaces

When you open an organization, you land on the **Workspaces** page. Select a workspace to access its resources. Resources like VMs, storage, networking, and SSH keys are scoped to the active workspace.

Every new organization starts with three workspaces — **production**, **dev**, and **stage**. An organization can have up to 5 workspaces; Admins can create more and rename them from the Workspaces page. See [Dashboard & navigation](/docs/getting-started/overview/dashboard#workspaces-page).

Organization-level concerns — billing, team, API tokens, and activity logs — are always accessible from the sidebar's **Organization** and **Billing** sections, regardless of which workspace is active.

## Billing scope

Billing is aggregated at the organization level. All resources across all workspaces in an organization share the same wallet balance, payment method, and invoices. Usage limits and quotas also apply at the organization level.

Before creating resources (VMs, block storage volumes), the platform checks the organization's billing state. If the wallet balance is insufficient or billing is suspended, a billing-blocked popup prompts you to add credits before proceeding.

## Best practices

* Use **one organization per billing entity** — each organization gets its own invoices and payment method.
* Use **workspaces to separate environments** — for example, the default `production`, `dev`, and `stage` workspaces within a single organization.
* Assign **least-privilege roles** to team members at the organization level.
* Use **API tokens** scoped to the whole organization, or to specific workspaces, for automation and CI/CD.

## Related pages

* [Create an organization](/docs/getting-started/account-setup/create-an-organization)
* [Organization settings](/docs/platform-fundamentals/organization-settings)
* [Billing and usage](/docs/platform-fundamentals/billing-and-usage)
* [Team members & access roles](/docs/platform-fundamentals/team-members-access-roles)
* [Dashboard](/docs/getting-started/overview/dashboard)