> ## Documentation Index
> Fetch the complete documentation index at: https://docs.guidinghand.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Orgs, people and API keys

> Orgs own agents, sessions, tasks and billing. People belong to orgs with a role; integrations use an org API key.

An **org** is your team's workspace. Its agents, sessions, tasks, recordings, settings and plan all belong to it, and nothing is shared between orgs. The org's address (its slug, such as `acme`) appears in every invite link: `https://guidinghand.ai/acme/K7QM-24XP`.

People sign in with Google. The first sign-in either joins the orgs that invited that email address or creates the person's first org on the free plan. One person can belong to several orgs and switch between them in the console.

The customer at the computer is never part of an org and never needs an account.

## Roles

| Role     | Can                                                                                                                              |
| -------- | -------------------------------------------------------------------------------------------------------------------------------- |
| `member` | Create sessions, run tasks, see history and replays.                                                                             |
| `admin`  | Everything a member can, plus manage agents, invites, API keys, webhooks, retention settings and the audit log. Delete sessions. |
| `owner`  | Everything an admin can, plus billing, the org's address, and making other people owners.                                        |

An org always keeps at least one owner.

## Inviting people

Admins invite people from the **Members** page of the console with an email address and a role. The invite link is valid for 7 days and only works for that email address.

## API keys

Integrations authenticate with an **org API key**, sent as a bearer token:

```bash theme={null}
curl https://guidinghand.ai/v1/sessions \
  -H "Authorization: Bearer $GUIDINGHAND_API_KEY"
```

* Admins create keys in the console under **Settings → API keys**. Keys start with `gh_live_` and are shown once, when created. GuidingHand stores only a hash.
* A key belongs to one org and acts with the admin role in it: it can manage agents and the webhook and delete sessions, but it can't create other keys, change members or touch billing. Those need a person.
* Revoke a key in the same place. Requests with it fail with `401 authentication` right away.

Keep keys on your servers. Don't put them in a browser, a mobile app or the desktop app your customers run.

<Note>
  If you belong to several orgs, make a key in each. A key never reaches another org's data.
</Note>

## Audit log

Admins see the org's audit log in the console under **Settings → Audit log**. It records who did what and when, including:

* agents created, changed, reset and deleted,
* sessions created and deleted (with their recordings),
* API keys created and revoked,
* webhook endpoint changes,
* recording and retention changes, and changes to members and invites.

Actions taken with an API key show as "API key" rather than a person.

## Plan and usage

The plan belongs to the org. Owners pick a plan and manage billing in the console under **Settings → Plan and usage**, which also shows the agent minutes used. See [billing](/concepts/tasks#billing) for what counts as an agent minute.
