Organization & Access Management.
Spin up an organization in one click, invite your team, and assign roles — no sales call. A single API key becomes an AI control plane for your org, with SSO, audit trails, and shared governance across every key and member.
Roles
Five roles, enforced server-side
Owner — full control: billing, team, every key and policy
Admin — manage members, API keys, and guardrail policy
Admin (read-only) — SOC 2-friendly auditor seat: read everything, change nothing
Member — use the gateway, manage their own keys and policies
End-user — governed Copilot-only seat: no dashboard, no key minting
↳ Roles are checked on every mutating request at the proxy layer — not just hidden in the UI.
Capabilities
What the control plane covers
Self-serve organization workspaces
Create an organization from the dashboard in a click, invite teammates by email, and switch between your personal and team workspaces — every resource re-scopes to the active org. Available on Pro and Enterprise, no sales call required.
Role-based access control
Five roles — Owner, Admin, Admin (read-only), Member, End-user — enforced server-side on every mutating request, not just in the dashboard UI.
Team & member management
Invite teammates by email, assign roles, remove or suspend access. Member groups are reusable entitlement profiles: which model tiers, monthly token budget, and guardrail policy a group of members gets.
SSO / SAML
SAML 2.0 single sign-on with Okta, Azure AD, and Google Workspace. Every SSO login is audit-logged. Available on Enterprise.
Audit log & compliance export
Append-only event log of every sensitive action — key creation, policy changes, billing credits, role changes. Cursor-paginated API plus NDJSON streaming export for SOC 2 evidence. Available on Enterprise.
Organization-wide governance
One shared weighted-token pool across all of an org's API keys — no multi-key gaming. Custom per-org rate limits and org-wide guardrail policy groups, managed centrally. Available on Enterprise.
Data-residency controls
Per-key region-lock so an API key only ever routes to allowed regions — Indonesia-first for UU PDP readiness. Available on Pro and above.
Why it matters
Governance is the moat, not just volume
A raw API key doesn't know who used it, what it was allowed to do, or which region it should have stayed in. Create an organization workspace on Pro or Enterprise and every key gets an owner, every action an audit trail, and every member group a budget and a policy — the layer that turns Anoman from a routing proxy into an AI control plane you can actually govern, self-serve from day one.