Concepts
How Pulumi Cloud models your organization and who can do what inside it. Read these to understand the system; see Guides for the procedures that configure it.
Organization and identity
- Organizations — the top-level container that owns your stacks, environments, and settings.
- Accounts — individual user accounts, profiles, and identity providers.
- Agent accounts — accounts for AI agents and automation acting on your organization’s behalf.
- Billing managers — the role that delegates billing access without granting admin rights.
- Access tokens — personal, team, and organization tokens for authenticating the CLI, CI/CD, and the REST API.
Access control
- Role-based access control (RBAC) — entities, scopes, permission sets, roles, and teams, and how permissions accumulate across them.
Security and compliance
- Audit logs — the record of user and system activity in your organization.
- Customer managed keys — using your own encryption keys to protect data at rest, currently for Pulumi ESC with AWS KMS.