Identity and authorization
- Organization roles are ordered owner, admin, and member. Each operation declares its minimum role, and the control plane applies that rule to dashboard sessions and organization API keys.
- Organization API keys are scoped to one organization. Only a SHA-256 digest is stored after the full key is shown once.
- A request for another organization does not reveal whether the addressed resource exists. Public errors use stable, redacted codes for automation.