Organizations
The tenant. What Madebook holds about one, what Bookbag holds, the four-step creation wizard, and every setting on the settings page.
An organization is the tenant. Every row Madebook stores carries one. It is the boundary that makes a cross-tenant read impossible rather than merely discouraged: a Madebook engineer embedded at two customers is one account with two memberships, holding a different role in each.
Where an organization lives
The organization itself — its name, its people and their roles — lives at Bookbag, shared by every product in the family. Madebook stores no organization table and no membership table. It asks Bookbag, server to server, and caches the answer for 15 seconds.
What Madebook does hold, one row per organization:
| Madebook's own record | What it holds |
|---|---|
| Settings | Telemetry mode, prompt retention, code retention |
| Billing | Plan, status, trial end, Stripe references, seats |
| Knowledge | A distilled document that field suggestions draft from |
| Connections | GitHub connections, which repositories are offered, and the API tokens engineers' editors present |
Plus every workspace, repository, mission, session, policy and audit event that belongs to it.
Creating one
Any signed-in account can create an organization and becomes its owner. There is no tenant to scope the request to before the tenant exists — that is how a company arrives.
Go to Organizations → New organization. The page is titled "Set up your organization" and says so up front:
Four steps, taken in order. Nothing is created until the last one — close this page and nothing exists.
Each step shows about a minute of work in the progress bar. A step is marked done, optional, still outstanding, or locked until the steps before it are done.
Step 1 — Who you are
Headed "What is this organization?"
These fields are not decoration — every workspace's context inherits from them, and the Skill Router matches on the industry.
| Field | Control | Example / default | Required |
|---|---|---|---|
| Name | Text | Acme Financial |
Yes |
| Industry | Text | Insurance — the Skill Router matches on it |
Yes |
| Website | Text | https://acme-financial.example |
No |
| Timezone | Picker | Defaults to America/Chicago |
No |
| What they do | Textarea, 3 rows | "A mid-market property and casualty insurer. The claims process is the commercial differentiator." | Yes |
Next stays disabled until name, industry and description are all non-blank; hovering it says "Name, industry and description are all needed."
Step 2 — What agents may use
Headed "What agents here are allowed to use".
An allow-list, not a preference. Everything picked here is created with the organization — nothing is saved yet.
If nothing is picked yet, a one-click banner offers "Use the recommended setup": Anthropic with its catalogued models, four coding clients (claude_code, cursor, vscode, codex), and the first two starter policy templates. It sets them as picks you can change, not decisions made for you.
Four blocks, each of which tells you what is wrong while it is empty:
| Block | The warning while empty |
|---|---|
| Providers | "No AI provider picked — every AI run for this organization would be refused." |
| Models | "No model picked." Before a provider is picked: "Pick a provider first — the models on offer follow from it." |
| Coding clients | "No coding client picked — no agent session could open." |
| Policies (optional) | "None picked — start from a template now, or add policies later under Governance." |
The model block has a Pick all button and an Add a model by name control for a self-hosted or Azure deployment, because no catalog can know what you called yours. The identifier is matched exactly as written, ignoring case — a near-miss is a model that never matches.
The providers you can pick from are anthropic, openai, deepseek, xai, google, azure_openai and local. The clients are Claude Code, Cursor, VS Code, Codex, GitHub Copilot, Windsurf and Other.
Next is disabled until a provider, a model and a client are all picked.
Step 3 — Who is here (optional)
Optional — the People page invites just as well later. Anyone added here is invited when the organization is created, not before.
The People page it refers to is the organization's Members & access page at Bookbag account; Madebook has no People page of its own.
Each row takes an Email, a Name, and a Role from Organization admin, Member or Viewer (default Member). Owner is not on the list. Adding an address already on the list says "Already on the list."
The button reads Next if you added anyone and Skip for now if you did not.
Step 4 — Review and create
Here is everything this walkthrough decided. One button creates all of it — until then, nothing exists.
The summary lists the organization, providers, models, coding tools, policies and invitations, with "none — add policies later under Governance" and "none — invite people later from the People page" where a section was skipped. It also notes that no connection keys are created here.
What is written, in order
When you press create, this happens:
- Policy templates are resolved. An unknown key fails with
Unknown policy template "<key>". - If any invitation address is your own, the request fails with "You are already here — invite someone other than yourself."
- The organization is created at Bookbag, with you as owner. Madebook then creates its own settings row.
- One approved provider record per provider.
- One approved model record per unique
provider:identifier, lower-cased, with usegeneral. - One approved client record per client.
- Policies from the templates, each
activeat version 1, with their rules (in order) and actions. - Invitations last, one call to Bookbag each.
- An audit event,
organization.created.
There is no transaction across these steps. A failure partway through leaves what was already written in place.
Caps on that request: 1–7 providers, 1–100 models, 1–7 clients, at most 20 policy templates, at most 50 invitations.
After it is created
A done screen says "
is brand new and you are its first engineer, so we suggest creating your own API key now. Everyone needs their own key to report their work into this organization — it is how your coding tool (Claude Code, Cursor) connects, and how sessions show up under your name.
Skipping is fine; any engineer can create one later under Organization → MCP tokens. See API tokens.
One organization across products
Bookbag, Openbook and Madebook share the organization — the same record, the same members, the same roles, one sign-in. Two things follow from that in the interface:
- The app switcher (the nine dots in the top bar) opens the other product on the organization you are in, not on its home page. Switching from Acme's Madebook lands on Acme's Openbook.
- A workspace can be created in several products at once. The workspace walkthrough offers Also create it in CodeBook and OpenBook; they offer the same checkboxes back. See Creating a workspace.
Managing people
There is no people page in Madebook. Who is in an organization, their roles and their invitations are managed on the organization's page at your Bookbag account (sso.bookbag.ai/user/organizations/<id>, under Members & access), once, for every product at the same time.
A copy of a permission list would be a place for two answers to the same question, so Madebook keeps none.
The ways there from Madebook, each opening Bookbag account in a new tab:
- Manage organization ↗ and the Members tile on the organization's Home;
- Manage ↗ on the People panel, and People and access ↗ in the Organization panel, on Overview;
- Invite people ↗ in the setup walkthrough;
- the old address
/organizations/<id>/people, which redirects there.
Madebook has no API for adding, removing, re-roling or re-inviting people any more; those actions were removed along with the page that used them.
Overview's People panel is read-only: the first six members with their initials, name or email, and their job title or role.
Bookbag enforces the membership rules: exactly one owner, owner and admin manage people, only the owner deletes the organization or transfers it.
A member in Madebook's view is either pending or not. Pending means Bookbag has not linked them to a registered account. Someone registered at Bookbag who has not yet opened Madebook shows the same way in the member list — pending either way, from Madebook's point of view. The Members count on Home leaves pending members out.
The setup checklist
The sidebar puts a red dot on a section whose data has not been put in. Every reason is a fact about the rows, never a guess about what you meant to do. A section with no reasons gets no dot.
For an organization, these are all the reasons:
| Section | Reason |
|---|---|
| Governance | "No AI provider is approved — every AI run for this organization is refused." |
| Governance | "No model is approved." |
| Governance | "No coding client is approved — no agent session can open." |
| Governance | "No policies. Start from a template." |
| People | "You are the only member. Invite the people who will supervise the work." |
| Connections | "No API token — no coding client can connect through the MCP." |
| Settings | "No description of what this organization is and does." |
| Settings | "No industry." |
| Skills | "No organization skill yet — the conventions every agent here should follow." |
Admins see these gathered on the organization's Overview page under a callout headed "Not set up yet", with a Walk through setup button. The People reason links to Bookbag account, where people are invited. The organization sidebar has no People row any more, so that reason shows on Overview rather than as a sidebar dot. See Home and Overview.
Settings
Organization → Settings has four panels.
The organization
Shared across Openbook, Madebook and Bookbag, and edited at your Bookbag account.
Read-only here: Name, Industry, Website, Timezone, What they do (which reads "Nothing written yet." when empty). Admins get an Edit at Bookbag account button that leaves for Bookbag.
The one exception: on the organization home page, an admin can click the title itself to rename it. A pencil appears on hover with the tooltip "Rename this organization". Enter saves, Escape reverts, and the name is trimmed to 120 characters.
Telemetry
Read-only. See Telemetry and retention for what each mode means and where it is actually changed.
What Madebook knows
The knowledge document field suggestions draft from — distilled from your website and everything written into Madebook.
Admins get Build it now / Rebuild. When nothing has been built, the panel says the first click of Suggest on any workspace form builds it automatically. When something has been built it shows when, which URL was read, the model used, and a Read the document toggle. Two badges can appear: "no AI model — raw data only" and "behind your data — rebuild recommended".
Delete this organization
Owner only. Refused while it still has workspaces — archive or delete those first.
The owner types the organization's name to confirm. The modal names what goes: "the organization — its members, invitations, tokens, governance decisions and audit trail".
If workspaces still exist the request is refused with the count:
Acme Financial still has 3 workspace(s). Archive or delete them first, or suspend the organization instead.
There are deliberately no platform-admin controls for suspending, archiving, deleting or renaming an organization. The tenant is Bookbag's, so that decision is made once there, for every product at once.
Plans
Every organization starts on Free with a 14-day trial.
| Plan | What it covers | Workspaces | Repositories | Evidence kept |
|---|---|---|---|---|
| Free | One workspace, one repository. Collision detection and context briefing. | 1 | 1 | 14 days |
| Pro | Every workspace, observed evidence from CI, the full change record. | unlimited | unlimited | 180 days |
| Business | Governance, policy enforcement, the audit export and SSO. | unlimited | unlimited | 1095 days |
Default list prices are $29/month or $290/year for Pro, and $79/month or $790/year for Business. A subscription status mirrors Stripe — trialing, active, past_due, canceled — with one Madebook value of its own, comped.
Seats billed to Stripe are stored; the member count is always counted live rather than read from that number.
If Bookbag is unreachable
Organization reads never throw. A failure answers conservatively — no organizations, no role — so an outage narrows access and never widens it. The call times out after 6 seconds.
Every write forwards to Bookbag and reports its refusal plainly rather than pretending it worked:
Bookbag SSO would not create the organization.Bookbag SSO would not save the organization.Bookbag SSO would not delete the organization.
Adding, removing and re-roling people, resending invitations and transferring ownership are not Madebook writes any more; they happen at Bookbag account.