Help & Guides
Your guide to understanding and using the Alkimi platform.
Organization
The Organization section is the administrative control tower for your workspace. It provides a centralized view of your team's structure, usage, and security settings. Whether you are managing a small research group or a large enterprise deployment, this is where you define the boundaries and rules that govern your collaborative environment.
From this dashboard, you can invite members and assign granular roles, monitor API usage across different projects, and manage billing and subscription details. It allows you to ensure that the right people have access to the right resources while maintaining strict oversight of your organization's data and costs.
Profile
This page allows you to manage your organization's core information. You can update your organization's name and icon, and view key metadata including the unique Organization ID, organization type (e.g., Corporate, Education), creation date, and when it was last updated.
Additionally, this section contains the "Danger Zone," where you can permanently delete the organization. This action is irreversible and will remove all associated data, including agents, knowledge collections, and user information.
Members
This is where you manage who has access to your organization. Adding members may affect your subscription cost, depending on your plan. For details, please see our Billing & Pricing documentation.
Credit Cap Settings
At the top of the Members page you can set a Default Monthly Credit Cap: the number of credits any member may spend per month before their chats stop until the cycle resets. Individual members can be given their own monthly cap (minimum 500 credits) that overrides the default, and roles can carry a cap too. Each member row shows their usage against the cap that applies to them, with the bar turning yellow at 80% and red at 95%.
You can also pause spending for a member from their row without touching their cap. A paused member keeps their access but cannot send messages that cost credits until you resume them; the row shows a Paused badge while it is in effect.
Member Tabs
- Members: Lists all the human users in your organization. You can manage their roles, view their credit usage, or remove them.
- Service Accounts: Lists non-human accounts used for automated workflows and API access. Each service account has a specific role assigned to it, and its API keys will be limited to that role's permissions.
- External Members: Shows users from outside your organization who have been granted access to specific resources (such as individual agents or collections) without being full org members.
- Pending Invitations: Shows email invitations that have been sent but not yet accepted or declined. You can revoke invitations from this list; to re-send, revoke and create a new invitation.
Inviting Members: Click the "Invite Member" button to send an invitation via email, or switch to the Link tab to create a shareable invite link instead. You must assign a role to each new member, which determines their permissions within the organization.
Roles
Organization roles control what members can do across the organization. Unlike agent and collection roles (which are fixed), organization roles are fully customizable. Members can hold multiple roles, and their effective permissions are the union of all assigned roles.
Default Roles
Every new organization starts with four built-in roles. Admin and Member are protected — their name and permissions cannot be changed. Manager and Contributor can be renamed and have their permissions adjusted.
Admin
Full administrative control. Protected — permissions cannot be modified.
- Manage Settings
- Manage Members
- Manage Roles
- Manage Billing
- Create Workspaces
- Manage API Keys
- Manage Templates
- Delete Organization
Manager
Can manage billing, members, and templates.
- Manage Settings
- Manage Members
- Manage Roles
- Manage Billing
- Create Workspaces
- Manage API Keys
- Manage Templates
- Delete Organization
Contributor
Can create workspaces and access Studio.
- Manage Settings
- Manage Members
- Manage Roles
- Manage Billing
- Create Workspaces
- Manage API Keys
- Manage Templates
- Delete Organization
Member
Basic organization access. Protected — permissions cannot be modified.
- Manage Settings
- Manage Members
- Manage Roles
- Manage Billing
- Create Workspaces
- Manage API Keys
- Manage Templates
- Delete Organization
Custom Roles
Administrators can create custom roles with any combination of the permissions above. Each role can also have an optional monthly credit cap (minimum 500 credits when set), allowing you to limit spending for specific teams or user groups.
Permission Reference
All organization-level permissions and which default roles include them:
| Permission | Description | Admin | Manager | Contributor | Member |
|---|---|---|---|---|---|
| org:admin | Org-wide resource visibility, self-grant access, auto-join, and model configuration (enable/disable and bulk migration) | ✓ | — | — | — |
| org:settings:manage | Update organization name, profile, security, policies, and domains; view model configuration (changes require org:admin) | ✓ | — | — | — |
| org:members:manage | Invite, update roles, and remove members | ✓ | ✓ | — | — |
| org:external:manage | Invite and manage external (guest) members | ✓ | ✓ | — | — |
| org:roles:manage | Create, edit, and delete role definitions | ✓ | — | — | — |
| org:billing:manage | Manage subscriptions, payments, and billing history | ✓ | ✓ | — | — |
| org:workspaces:create | Create new workspaces | ✓ | — | ✓ | — |
| org:apikeys:manage | Create, update, and delete API keys | ✓ | — | — | — |
| org:apikeys:view | List and view API key details | ✓ | ✓ | — | — |
| org:templates:manage | Manage agent templates and instruction library | ✓ | ✓ | — | — |
| org:audit:view | View the organization audit log | ✓ | ✓ | — | — |
| org:studio:view | Access the Content Studio | ✓ | ✓ | ✓ | ✓ |
| org:delete | Delete the organization (restricted to Admin) | ✓ | — | — | — |
Constraints & Limitations
- Restricted permissions: Custom roles cannot include
org:admin,org:deleteororg:roles:manage— these are reserved for the Admin system role. - Re-authentication: Editing roles (and most organization settings) prompts you to re-enter your password or passkey.
- Admin role: Fully immutable — name, description, permissions, and credit cap cannot be changed.
- Member role: Name and permissions are locked; only description and credit cap can be edited.
- Manager & Contributor: Fully editable — can be renamed, have permissions added/removed, and have credit caps set.
- Deletion: System roles cannot be deleted. Custom roles can only be deleted if no members are currently assigned to them.
- Feature-gated: Some permissions (e.g.,
org:audit:view,org:studio:view) are hidden when the corresponding feature flag is not enabled on the organization.
Security
The Security page provides organization-wide authentication and access controls that apply to all members.
- Require Two-Factor Authentication: Enforce that all members must have two-factor authentication enabled on their accounts. When turned on, members who haven't set up 2FA will be prompted to do so, and they cannot disable it while the policy is active. See the Account Security section for how individual users set up 2FA.
- Invitation Policies: Control how invitations work, including setting a maximum invitation expiry (in days) and restricting invitations to specific email domains (e.g., only allow @yourcompany.com addresses).
- Verified Domains: Register and verify your organization's domain via DNS to establish trust and enable domain-based policies.
Policies
The Policies page lets administrators define organization-wide content and sharing rules that apply to all agents and members.
- External Sharing: Control how agents and content can be shared outside your organization with three modes:
- Unrestricted: No organization-wide restrictions; each agent's public access settings are respected individually.
- Enforced: External sharing follows per-agent settings but with additional organizational controls and PII detection applied.
- Organization Only: Share links are restricted to signed-in members of your organization; external links cannot be created and existing ones stop working.
- PII Detection: Configure how personally identifiable information is handled. Set per-category actions (warn, block, or redact) for different types of PII detected in shared content.
- Safeguard Defaults: Define the default set of safeguards that are automatically applied to new agents. This ensures a consistent baseline of safety measures across your organization while allowing individual agents to be further customized.
Models
Control which AI models are available to your organization's agents. Two pages, Language Models and Image Models, list every globally available model of that kind and let administrators enable or disable specific ones. When a model is disabled, agents using that model will need to be migrated to an alternative before they can be used.
The Alkimi routers (Alkimi Auto, the tier routers and Alkimi Image; see Alkimi Routers) appear in this list too and can be disabled like any model. Disabling an individual model does not break agents on a router: the router moves to the next best model your organization still allows. Disabling a router itself removes it from your agents' pickers.
A router has no availability of its own. If you disable every model it could route to (every chat model for the Alkimi tier and Auto routers, every model of a creator for a creator router, every image model for Alkimi Image), the router shows a No models to route to badge, is hidden from agent pickers, and cannot be switched on until one of those models is enabled again. Agents still using such a router are offered a replacement in the Migrate dialog before the change is saved.
Default Agent
Pin one agent to the navigation rail so members can start a new chat with it in a single click from anywhere in the organization. Requires the Manage Settings permission.
API Keys
Generate and manage API keys to integrate Alkimi with other applications and build custom workflows. API usage is metered and will consume credits from your account. For detailed endpoint information, see the full API Documentation, and for pricing details, see our Billing & Pricing documentation. It's critical to treat API keys like passwords—do not expose them in client-side code or commit them to version control.
Key Types
There are two types of API keys you can create:
- Personal Key: This key is tied to your user account and inherits all of your permissions. It's useful for personal scripts or applications.
- Service Account Key: This creates a new, non-human user in your organization. You assign a specific role to it, and the key's permissions are limited to that role. This is the recommended approach for applications and automated workflows, as it allows you to grant limited, specific access.
Agent Templates & Instruction Library
Share reusable agent configurations and instruction sections across your entire organization.
- Agent Templates: Organization-level templates that any member can use when creating new agents. These appear alongside personal templates in the creation dialog.
- Instruction Library: Shared instruction sections that appear in the "Organization" tab when adding premade sections to an agent's instructions. This ensures consistent prompt patterns across your team.
- Web Sources: Add public domains as organization-wide shortcuts in the
@websource picker, alongside the built-in source groups available to all users.
Integrations
Connect your organization to learning management systems such as Canvas. Once connected, workspaces can use Canvas Roster Sync and collections can be created from Canvas modules.
Billing
The billing section provides a comprehensive set of tools for managing your organization's subscription, credits, and financial records. For a detailed breakdown of our pricing, plans, and credit system, please see our full Billing & Pricing documentation.
Subscription
Manage your organization's subscription plan. You can view your current plan details, upgrade or downgrade, and access the Stripe Customer Portal for payment method management. Plan changes apply immediately, with the price difference prorated for the rest of the billing period; a cancellation takes effect at the end of the current billing period.
Team plans are priced per seat, and credits are pooled: your monthly allowance is the plan's credits per seat multiplied by the seats you purchase, shared by every member of the organization. The current plan card shows the number of active members alongside the number of seats you pay for, and each plan card lists its price and credit allowance per seat.
Credit Top-ups
If your organization needs additional capacity beyond its subscription limits, you can purchase one-time credit top-ups. These credits are added to your balance immediately. Unlike plan credits, which reset every billing cycle, top-up credits stay available for a fixed number of months from the date of purchase (3 months by default; the validity is shown on each bundle). Credits closest to expiring are spent first.
Note: You must have an active paid subscription to purchase top-ups. If your subscription is canceled or inactive, this feature will be disabled.
- Navigate to the Top-ups page (found in the sidebar under Organization).
- Select a credit bundle. Some larger bundles may include bonus credits (displayed in green).
- Click the Purchase button to be redirected to a secure checkout page.
For enterprise-grade purchases or custom credit requirements, please contact sales@alkimi.ai.
Invoices
Access your complete payment history and download past invoices. Each invoice includes a detailed breakdown of charges for your subscription and any credit top-ups.
Usage
Monitor your organization's credit consumption with detailed usage charts and breakdowns. Track spending patterns over time, identify which agents consume the most credits, and export usage data as CSV for external analysis.
Credit Alerts
Set up credit usage alerts to stay ahead of your spending. You can configure thresholds for both actual usage (alert when you've spent a certain percentage of your balance) and projected usage (alert when your current spending rate is on track to exceed your balance). Alerts are emailed to every member with the Manage Billing permission (Admins and Managers by default).
Activity (Audit Trail)
The Activity page provides a comprehensive audit trail of all significant actions taken within your organization. This is a critical tool for administrators to maintain security, ensure compliance, and troubleshoot changes.
- Membership Changes: When members are invited, join, leave, or are removed from the organization.
- Role & Permission Updates: Any changes to the roles assigned to members or service accounts.
- Security Events: Creation or deletion of API keys and changes to organization security settings.
- Billing & Subscription: Updates to your plan, credit top-ups, and changes to payment methods.
- Resource Management: Creation and deletion of agents and knowledge collections across the organization.
Each entry provides details on what changed, who performed the action, and when it occurred. Administrators can use built-in filters to drill down into specific event types or date ranges. Results can be exported as CSV.