Core concepts
Projects and organizations
organization ─ members (owner, admin, developer, viewer), plan
└ project ─ environments (development, production, …)
└ provider connections (one per provider) and environment secrets
Organizations
An organization is the billing entity and the unit of membership: it has a plan, members with roles, and an activity log. Every project belongs to exactly one organization.
People outside an organization can't tell that it exists: asking for its projects, or for an id from another organization, returns "not found", never "forbidden".
Members and roles
Owners and admins invite people by email from the Team page: the invitee gets a link, signs in or creates an account with that address, verifies it, and accepts (links last 7 days and work once). An existing account can also be added directly. Either way, membership only ever goes to someone who has proved they control the address (a verified email), because anyone can register an address they don't own. Only owners can invite or add owners, and the organization's plan limits how many members it has.
| Role | Can |
|---|---|
| viewer | Read the organization, projects, connections, secret names, Doctor results and the activity log; run Doctor |
| developer | Viewer, plus create projects and environments, connect and configure providers, write and reveal secrets, apply Doctor fixes, outside production |
| admin | Developer, plus the same in production, billable and destructive changes, deleting projects, managing members |
| owner | Admin, plus billing and deleting the organization |
Only owners can add or remove owners, and the last owner can't be removed. Roles are checked inside Ahena's core services, so the dashboard, CLI, MCP server and API all apply the same rules.
Projects
A project is one application. It starts with two environments,
development and production; add staging, preview or your own as you need them. In a
repository, ahena init links the directory to a project and writes ahena.config.ts
(configuration).
Each environment has its own provider connections, credentials, secrets, plans and Doctor results. Nothing falls back from one environment to another.
Sessions
How you reach Ahena decides what you can do, on top of your role:
| Session | Made by | Can't |
|---|---|---|
| Web | Signing in to the dashboard | (the only session that approves changes that matter) |
| CLI | ahena login |
Approve changes that matter: those wait for you in the dashboard |
| Agent | ahena mcp, from your CLI session |
Approve anything, reveal secrets, manage people, billing or the organization, create tokens |
| CI | ahena ci token create |
Anything but reading and running checks, for one project |
Details: Signing in · Approvals · CI/CD.