Skip to main content
Pulumi logo Pulumi logo
  1. Docs
  2. Administration
  3. Concepts

Concepts

    How Pulumi Cloud models your organization and who can do what inside it. Read these to understand the system; see Guides for the procedures that configure it.

    Organization and identity

    • Organizations — the top-level container that owns your stacks, environments, and settings.
    • Identity providers and SSO — SAML 2.0 single sign-on, GitHub, GitLab, or Bitbucket: the provider that governs who can be a member of your organization.
    • SCIM provisioning — how a SAML-backed organization synchronizes users and teams from its identity provider, and the behavior to plan for.
    • Accounts — individual user accounts, profiles, and identity providers.
    • Organization-managed users — accounts an organization creates and controls through SAML or SCIM, and the restrictions that come with them.
    • Agent accounts — accounts for AI agents and automation acting on your organization’s behalf.
    • Billing managers — the role that delegates billing access without granting admin rights.
    • Access tokens — personal, team, and organization tokens for authenticating the CLI, CI/CD, and the REST API.
    • OIDC issuers — trust relationships that let CI/CD systems and Kubernetes workloads exchange their own OIDC tokens for short-lived Pulumi access tokens.

    Access control

    Security and compliance

    • Audit logs — the record of user and system activity in your organization.
    • Customer managed keys — using your own encryption keys to protect data at rest, currently for Pulumi ESC with AWS KMS.

    Compute

    • Customer-managed runners — runners you host in your own infrastructure for deployments, Discovery scans, and audit policy evaluations.

      The infrastructure as code platform for any cloud.