# Organizations

An Avrea organization groups together users, GitHub App installations,
cache settings, and billing. A user can belong to multiple organizations and
switch between them from the org picker in the console.

## Roles

Every member of an organization has one of four roles. Roles are
hierarchical: each higher role (Owner > Admin > Billing admin > User) includes
every permission of the roles below it.

| Role | Adds |
|---|---|
| **Owner** | Full organization control. |
| **Admin** | Manage org settings, installations, email domains, and members. |
| **Billing admin** | View and manage billing, invoices, and payment methods. |
| **User** | Read access to workflows, jobs, logs, cache entries, and analytics. |

Roles are assigned per-organization. Owners and Admins can grant and change
roles for other members.

## Adding members

There are two ways to bring people into an organization. Both live under
**Organization settings** → **Members**.

### Invite by email address

Owners and Admins can invite individual users by email. From the
**Invitations** section:

1. Enter the email address.
2. Click **Invite**.

The next time the recipient signs in to
[console.avrea.com](https://console.avrea.com) with that email, they'll see
an accept/decline prompt. On accept, they join as a **User**; you can
promote them afterward.

### Email-domain auto-join

For broader access, configure one or more **verified email domains** for the
organization. When anyone signs up with a verified email address in one of
those domains, they join as a **User** automatically — no per-person
invite needed.

To configure domains:

1. Open **Allow users with these email domains to automatically join**.
2. Pick a domain. You can only add domains that match one of your own
   verified email addresses, which prevents adding a domain you don't
   control.
3. **Save**.

From then on, new signups from that domain land directly in your
organization. Change their role afterward if they need more than read-only
access.

For centralized company sign-in, automatic member provisioning, and optional
enforcement on verified domains, see [SAML single sign-on](/saml-sso/).

## Billing

Billing is per-organization. Only **Owners** and **Billing admins** can see
the billing page, which lists current-period usage, invoices, payment
methods, billing contact emails, and tax ID.

Usage is metered by the minute per job and invoiced monthly. See
[Runners & Pricing](/runners/) for per-minute rates.

## Getting help with your organization

For things the console doesn't currently support (renaming an organization,
changing an owner, removing a member, or deleting an organization), reach
out to [support@avrea.com](mailto:support@avrea.com).