Teams — scoped views of who’s sending tokens
Group your org’s token senders — the people and machines streaming Claude Code, Cursor, Codex, Antigravity, GitHub Copilot, Hermes, and OpenClaw sessions into your dashboard — into named teams. Then decide what each member, and each MCP key, gets to see.
A named group of senders, one picker away
A team is a named group of your org’s token senders — “Financial Audit” might be six of your twenty-six. Owners and admins create and manage teams on the dashboard’s Team page.
- A scope picker sits in the dashboard header, next to the date range: the whole organization, or a single team.
- By default nothing changes — every member keeps seeing the whole org.
- Restricted members only see the teams they've been granted in the picker.
- Whole organization26 senders
- Financial Audit6 senders
- Backend11 senders
- Growth5 senders
Bring in an auditor without handing over the org
Admin and owner mean full access — too much for a project manager or an external auditor. Teams give you a third option: a member who sees exactly the slice they’re there for.
Create the team
On the dashboard's Team page, open Teams and hit New team. Name it and pick its senders — say, the six people and machines on the audit.
Invite them, scoped
Invite the auditor as a member with access to just that team. The invite email tells them exactly what they can see — access is pre-configured, nothing to accept or set up.
They see their slice
Every page — Overview, People, Sessions, Models, Repos, Activity — plus search and Ask Octarin only show data from their teams' senders. Nothing else exists for them.
Roles say what you can do. Teams say what you can see.
Roles — unchanged
The three roles you already have stay exactly as they are.
- owner
- everything, including org ownership
- admin
- manage members, teams, and keys
- member
- read the dashboard
Team access — a separate axis
Owners and admins can restrict any member to specific teams. The restriction follows them everywhere — every page, search, and Ask Octarin answer only draws from their teams’ senders.
Unrestricted members keep the whole-org view — nothing changes until you say so.
MCP keys that stop at the team line
The same scoping applies to machines. MCP keys — what lets Claude or Cursor query your org’s Octarin data — can be limited to teams.
- Members can mint keys only for teams they belong to.
- Admins can attach multiple teams — or the whole org — to a single key.
- Hand an auditor a key scoped to Financial Audit and their AI tools can only see that team's activity.
- name
- auditor-laptop
- key
- oct_mcp_••••••••42a7
- scope
- Financial Audit
› claude: what did the audit team ship this week? — answers stop at the team line.
What makes a good team
Teams work best when they mirror how the work is actually grouped — not how permissions ought to be carved up.
Name the work, not the rank
Use functional groups people already recognize: "Backend", "Financial Audit", "Growth". Avoid permission tiers like "Restricted" or "Level 2" — a team should describe what the senders do, not what a viewer may see.
Group by context
Put in the token senders whose work belongs to that context — people and machines alike. One sender can sit in several teams; membership is about where their sessions make sense, not org-chart lines.
No team is fine
Senders outside every team aren’t hidden — they still show up under "Whole organization". Teams are lenses you add on top of the org view, not walls you have to build around everyone.
Questions, answered honestly
Can one person be in several teams?
Yes. A sender can belong to any number of teams, and a member can be granted access to several — the scope picker lists each team they've been granted.
Do teams change anyone's role?
No. Roles stay owner, admin, and member. Team access is a separate restriction axis that only applies to members — owners and admins always see the whole organization.
Why can't a restricted member see the knowledge graph or Pulse?
The knowledge graph and Pulse are org-wide surfaces today, so they're hidden for group-restricted members rather than leaking data from outside their teams. Team filtering for both is coming.
Where does traffic without a sender go?
Telemetry that arrives with no sender attribution can’t be assigned to a team, so it’s excluded from team views. It stays visible under "Whole organization".
How fast do access changes apply?
Team and access changes can take up to about two minutes to propagate. If a freshly restricted member still sees the old scope, give it a moment.