An organization holds everything you run on EZGH Cloud: its members (users and bots), IAM policies, API keys, billing, Trails and projects. Every API call names its organization. An account belongs to at most one organization.
- Projects: create, rename and delete the projects in your organization.
Identifiers
| Field | Example | Notes |
|---|---|---|
id |
0199a3c2-5b1e-7d40-9f3a-2c8e6b1d4f70 |
UUID. API paths use it. |
slug |
org_k3f9a0x2m7qp |
org_ and 12 lowercase letters and digits. Generated, unique and never changes. |
resourceName |
ezgh::org_k3f9a0x2m7qp |
Names the organization in IAM policies. See IAM. |
name |
Acme |
1 to 100 characters. Needn’t be unique. |
Get them with ezgh orgs get or GetOrganization.
Create an organization
You create your organization during setup, right after sign-up.
You become its root user. If you already belong to an organization,
CreateOrganization returns 409 organization_exists.
API keys can’t create organizations.
Rename an organization
You need organizations.update. Renaming changes only name.
curl -X PATCH https://orgs.ezghcloud.com/v1/organizations/$ORG_ID \
-H "Authorization: Bearer $EZGH_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "name": "Acme Corp" }'See UpdateOrganization.
The root user
The account that creates the organization is its root user.
- Policies don’t restrict the root user: it can do everything in the organization.
AdministratorAccessis always attached to it and can’t be detached. - Only the root user, signed in to the console, can delete the organization or make someone
else root. API keys and
ezghCLI logins can’t, even the root user’s. - The root user can’t leave or be removed from the organization. Make someone else root first.
Make someone else root
You must be the root user, signed in to the console.
- In the console, open IAM > Users and select the user.
- Click Make root.
- Confirm with Make root.
You stop being root, but keep AdministratorAccess, attached like any other policy, until
someone detaches it. A user suspended by your identity provider can’t be made root.
Leave an organization
Any member except the root user can leave. Your group memberships and policies in the
organization are removed and your API keys for it are revoked. You must be signed in (a
browser session or an ezgh CLI login); API keys can’t leave.
ezgh orgs leaveCall LeaveOrganization with your session or CLI login.
If your identity provider manages your account over SCIM, you can’t leave: your administrator
removes you (409 managed_by_scim).
Delete an organization
Only the root user, signed in with a browser session, can delete an organization. API keys and
ezgh CLI logins can’t. The console doesn’t have a control for this yet; see
DeleteOrganization.
Deletion takes effect at once and can’t be undone:
- Its projects are deleted, and so are the OCR processors in them.
- Every member loses access. Its bots, API keys, groups, custom policies, invitations and SCIM tokens are deleted.
Project quota
An organization can have 10 projects by default. The quota is organizations.projects.count
(Projects per organization). It counts live projects: deleting a project frees its slot.
See Service quotas.
Creating a project over the limit returns 409 with the code quota_exceeded and no
Retry-After header:
{
"error": {
"code": "quota_exceeded",
"message": "This organization already has 10 projects, and can have at most 10 (organizations.projects.count)",
"quota": {
"id": "organizations.projects.count",
"kind": "allocation",
"scope": "organization",
"scopeResourceName": "ezgh::org_k3f9a0x2m7qp",
"limit": 10,
"used": 10
}
}
}Delete a project, then create the new one.