Skip to content

Organizations

Your organization, its root user, leaving and deleting it, and its project quota.

Updated View as Markdown

An organization holds everything you run on EZGH Cloud: its members (users and bots), IAM policies, API keys, billing, Trails and projects. Every API call names its organization. An account belongs to at most one organization.

  • Projects: create, rename and delete the projects in your organization.

Identifiers

Field Example Notes
id 0199a3c2-5b1e-7d40-9f3a-2c8e6b1d4f70 UUID. API paths use it.
slug org_k3f9a0x2m7qp org_ and 12 lowercase letters and digits. Generated, unique and never changes.
resourceName ezgh::org_k3f9a0x2m7qp Names the organization in IAM policies. See IAM.
name Acme 1 to 100 characters. Needn’t be unique.

Get them with ezgh orgs get or GetOrganization.

Create an organization

You create your organization during setup, right after sign-up. You become its root user. If you already belong to an organization, CreateOrganization returns 409 organization_exists. API keys can’t create organizations.

Rename an organization

You need organizations.update. Renaming changes only name.

curl -X PATCH https://orgs.ezghcloud.com/v1/organizations/$ORG_ID \
  -H "Authorization: Bearer $EZGH_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "name": "Acme Corp" }'

See UpdateOrganization.

The root user

The account that creates the organization is its root user.

  • Policies don’t restrict the root user: it can do everything in the organization. AdministratorAccess is always attached to it and can’t be detached.
  • Only the root user, signed in to the console, can delete the organization or make someone else root. API keys and ezgh CLI logins can’t, even the root user’s.
  • The root user can’t leave or be removed from the organization. Make someone else root first.

Make someone else root

You must be the root user, signed in to the console.

  1. In the console, open IAM > Users and select the user.
  2. Click Make root.
  3. Confirm with Make root.

You stop being root, but keep AdministratorAccess, attached like any other policy, until someone detaches it. A user suspended by your identity provider can’t be made root.

Leave an organization

Any member except the root user can leave. Your group memberships and policies in the organization are removed and your API keys for it are revoked. You must be signed in (a browser session or an ezgh CLI login); API keys can’t leave.

ezgh orgs leave

Call LeaveOrganization with your session or CLI login.

If your identity provider manages your account over SCIM, you can’t leave: your administrator removes you (409 managed_by_scim).

Delete an organization

Only the root user, signed in with a browser session, can delete an organization. API keys and ezgh CLI logins can’t. The console doesn’t have a control for this yet; see DeleteOrganization.

Deletion takes effect at once and can’t be undone:

  • Its projects are deleted, and so are the OCR processors in them.
  • Every member loses access. Its bots, API keys, groups, custom policies, invitations and SCIM tokens are deleted.

Project quota

An organization can have 10 projects by default. The quota is organizations.projects.count (Projects per organization). It counts live projects: deleting a project frees its slot. See Service quotas.

Creating a project over the limit returns 409 with the code quota_exceeded and no Retry-After header:

{
  "error": {
    "code": "quota_exceeded",
    "message": "This organization already has 10 projects, and can have at most 10 (organizations.projects.count)",
    "quota": {
      "id": "organizations.projects.count",
      "kind": "allocation",
      "scope": "organization",
      "scopeResourceName": "ezgh::org_k3f9a0x2m7qp",
      "limit": 10,
      "used": 10
    }
  }
}

Delete a project, then create the new one.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close