Documentation menu

Core concepts

Projects and organizations

organization ─ members (owner, admin, developer, viewer), plan
  └ project ─ environments (development, production, …)
               └ provider connections (one per provider) and environment secrets

Organizations

An organization is the billing entity and the unit of membership: it has a plan, members with roles, and an activity log. Every project belongs to exactly one organization.

People outside an organization can't tell that it exists: asking for its projects, or for an id from another organization, returns "not found", never "forbidden".

Members and roles

Owners and admins invite people by email from the Team page: the invitee gets a link, signs in or creates an account with that address, verifies it, and accepts (links last 7 days and work once). An existing account can also be added directly. Either way, membership only ever goes to someone who has proved they control the address (a verified email), because anyone can register an address they don't own. Only owners can invite or add owners, and the organization's plan limits how many members it has.

Role Can
viewer Read the organization, projects, connections, secret names, Doctor results and the activity log; run Doctor
developer Viewer, plus create projects and environments, connect and configure providers, write and reveal secrets, apply Doctor fixes, outside production
admin Developer, plus the same in production, billable and destructive changes, deleting projects, managing members
owner Admin, plus billing and deleting the organization

Only owners can add or remove owners, and the last owner can't be removed. Roles are checked inside Ahena's core services, so the dashboard, CLI, MCP server and API all apply the same rules.

Projects

A project is one application. It starts with two environments, development and production; add staging, preview or your own as you need them. In a repository, ahena init links the directory to a project and writes ahena.config.ts (configuration).

Each environment has its own provider connections, credentials, secrets, plans and Doctor results. Nothing falls back from one environment to another.

Sessions

How you reach Ahena decides what you can do, on top of your role:

Session Made by Can't
Web Signing in to the dashboard (the only session that approves changes that matter)
CLI ahena login Approve changes that matter: those wait for you in the dashboard
Agent ahena mcp, from your CLI session Approve anything, reveal secrets, manage people, billing or the organization, create tokens
CI ahena ci token create Anything but reading and running checks, for one project

Details: Signing in · Approvals · CI/CD.