acme) appears in every invite link: https://guidinghand.ai/acme/K7QM-24XP.
People sign in with Google. The first sign-in either joins the orgs that invited that email address or creates the person’s first org on the free plan. One person can belong to several orgs and switch between them in the console.
The customer at the computer is never part of an org and never needs an account.
Roles
An org always keeps at least one owner.
Inviting people
Admins invite people from the Members page of the console with an email address and a role. The invite link is valid for 7 days and only works for that email address.API keys
Integrations authenticate with an org API key, sent as a bearer token:- Admins create keys in the console under Settings → API keys. Keys start with
gh_live_and are shown once, when created. GuidingHand stores only a hash. - A key belongs to one org and acts with the admin role in it: it can manage agents and the webhook and delete sessions, but it can’t create other keys, change members or touch billing. Those need a person.
- Revoke a key in the same place. Requests with it fail with
401 authenticationright away.
If you belong to several orgs, make a key in each. A key never reaches another org’s data.
Audit log
Admins see the org’s audit log in the console under Settings → Audit log. It records who did what and when, including:- agents created, changed, reset and deleted,
- sessions created and deleted (with their recordings),
- API keys created and revoked,
- webhook endpoint changes,
- recording and retention changes, and changes to members and invites.