Concepts
How Pulumi Cloud models your organization and who can do what inside it. Read these to understand the system; see Guides for the procedures that configure it.
Organization and identity
- Organizations — the top-level container that owns your stacks, environments, and settings.
- Identity providers and SSO — SAML 2.0 single sign-on, GitHub, GitLab, or Bitbucket: the provider that governs who can be a member of your organization.
- SCIM provisioning — how a SAML-backed organization synchronizes users and teams from its identity provider, and the behavior to plan for.
- Accounts — individual user accounts, profiles, and identity providers.
- Organization-managed users — accounts an organization creates and controls through SAML or SCIM, and the restrictions that come with them.
- Agent accounts — accounts for AI agents and automation acting on your organization’s behalf.
- Billing managers — the role that delegates billing access without granting admin rights.
- Access tokens — personal, team, and organization tokens for authenticating the CLI, CI/CD, and the REST API.
- OIDC issuers — trust relationships that let CI/CD systems and Kubernetes workloads exchange their own OIDC tokens for short-lived Pulumi access tokens.
Access control
- Role-based access control (RBAC) — entities, scopes, permission sets, roles, and teams, and how permissions accumulate across them.
Security and compliance
- Audit logs — the record of user and system activity in your organization.
- Customer managed keys — using your own encryption keys to protect data at rest, currently for Pulumi ESC with AWS KMS.
Compute
- Customer-managed runners — runners you host in your own infrastructure for deployments, Discovery scans, and audit policy evaluations.