Control membership and keep each organization’s data and actions scoped.
Organizations isolate sessions, evaluations, audits, issues, alerts, queries, dashboards, users, and keys. Confirm the active organization before changing administrative resources.
Administrators can create, update, disable, and re-enable users, then assign the permission set appropriate for their role. The API uses a delete operation for disabling, but it does not remove the account or its membership record.
Disabling a user blocks that identity from signing in to every organization, not only the organization currently selected. Re-enabling restores global sign-in and the member’s permissions in this organization.
Give service accounts descriptive names tied to a workload and owner. Avoid sharing keys between organizations or between people and machines.