Roles
There are two roles: Member and Admin. A role is held per team, so the same person can be an admin of one team and a member of another.
Admin rights descend. An admin of a team is an admin of every team beneath it. An admin of the organization itself, the team at the top, is therefore an admin everywhere.
Organization admins can also see the full member list and deactivate or restore members.
There is no owner role. The top of the tree is your organization, and its admins hold the highest rights.
Invitations
An admin invites someone by email and picks the role they land in.1
Send
Alkera emails a signup link. The invitation is good for seven days, and only one invitation can be pending for an email on a team at a time.
2
Accept
The recipient signs up through the link, or accepts from inside Alkera if they already have an account. They join the team and every team above it.
Signing in
Members sign in with an email and password, with Google, or with GitHub. Organization admins can disable these alternative login methods or even configure SSO. Accounts can add two-factor authentication with an authenticator app and one-time backup codes.Preconfigured connections
Instead of every person setting up the same connection from scratch, an admin can set one up once for the whole organization. Members get it ready to use. This is most useful when a shared secret is involved. An admin provides it a single time, and members connect through it without ever seeing it. For example, this is especially useful for BigQuery OAuth where the OAuth secret can not be exposed. When pre-configured, each member then authorizes with their own identity.Enterprise access
Organizations on an enterprise plan can connect an identity provider and enforce it for everyone.- Single sign-on over OIDC or SAML 2.0, configured per organization. Once enforced, password sign-in can be disabled.
- Directory sync with SCIM 2.0, to provision and deprovision members from your directory. It can run with or without SSO sign-in enabled.
- Audit log of activity in your organization.
Related
Agent & Tools
Permission modes and what the agent is allowed to do.
Plugins & Connections
How Alkera reaches your data stack.