Organizations
The tenant boundary in aethercert: creating one, switching between them, the organization settings pages, billing, and deleting one.
Everything in aethercert belongs to an organization: domains, agents, certificates, authorities, deploy targets, members and the event log. It is the boundary that matters
- nothing is visible across one without being explicitly given access.
A person can belong to several organizations and switches between them from the sidebar. Under an MSP plan, each customer is a separate organization rather than a filtered view of a shared one.
The first organization
An organization is created once, on the onboarding screen shown the first time an account signs in belonging to none. It asks for a name, then a contact name, email, phone, street address, city and postal code - all required, so billing and support have somewhere real to reach.
Being invited to an existing organization does not create a second one. An invited colleague joins the organization that invited them, and if an invitation is already waiting when they first sign in, the same screen offers to accept it instead of starting a new workspace - with no contact details needed, since that organization already has its own.
After that, the only ways to reach another organization are being invited to it, or - on an MSP plan - creating a customer workspace.
Switching organizations
The switcher in the sidebar lists every organization you can reach: the ones you belong to, plus the managed workspaces your membership covers. The choice is remembered per session, and everything on screen - certificates, agents, the event log - is scoped to the active one.
Organization settings
Settings sit under the account menu, in two groups.
Personal - your account, the same everywhere you use it:
| Page | What is on it |
|---|---|
| Profile | First and last name, display name, phone, time zone, date and time format, language, and a download of your own data. |
| Appearance | Light, dark or system theme. |
| Notifications | Which aethercert system emails you receive. Security notifications cannot be turned off. |
| Security | Linked sign-in methods, password, authenticator apps, passkeys, and account deletion. |
| Sessions | The current device, and sign-out everywhere or everywhere-but-here. |
Organization - scoped to whichever organization is active:
| Page | What is on it | Who |
|---|---|---|
| General | Company profile, contact details, default language, organization ID, creation date, the fleet-wide update channel, and - on an MSP plan - the partner-directory listing. | Owner |
| Roles | What each of the four roles may do. Read-only; roles are assigned on Members. | Everyone |
| Audit log | Security- and configuration-relevant events for this organization. | Everyone |
| Members | Invite, change roles, set customer access, remove, reset another member's second factor. | Owner |
| Authentication | Single sign-on with Microsoft Entra ID. | Owner |
| Billing | Plan, usage against each limit, invoices, payment method, MSP customer slots. | Owner |
| Branding | White-label company name, logos, favicon, theme, font and support details. | Owner, MSP Plus |
| Danger zone | Transfer ownership to another member, detach from an MSP, or delete the organization. | Owner |
Individual remote sessions cannot be listed or revoked one by one - the identity provider does not expose a per-device session list - so Sessions offers ending every other session at once, or every session including this one.
Billing
Settings > Organization > Billing shows the current plan and how much of each limit the organization is using, with tabs for invoices and the payment method. Upgrades take effect immediately. A downgrade to a cheaper paid plan is scheduled through Stripe and takes effect at the end of the current period; until then the banner offers to cancel it.
A workspace whose licence comes from an MSP's slot pool cannot change its own plan. Its billing page says who manages it and how to reach them; becoming independent means asking that MSP to detach the workspace first. See MSP customer workspaces.
What each plan allows is in Plans and limits.
The partner directory
An organization on an MSP plan can opt in to the partner directory from Settings > Organization > General. Listing publishes its company name, contact person, email, phone and city - plus a short description you write - to every aethercert organization that does not already have an MSP, under Help > Support. It is off by default and only an owner can turn it on.
The update channel
Settings > Organization > General carries the organization-wide update channel -
which release ring its agents and connectors are offered builds from. It defaults to
stable. An individual agent can override it, which is what you want for canarying a
build on one host rather than the fleet. See
Updates and release channels.
Deleting an organization
Settings > Organization > Danger zone, owner only. Deletion cascades: agents, certificates, domains, authorities, deploy targets, jobs and the event log go with it.
It does not reach onto any host. Certificates already deployed keep working until they expire, and agents keep running until somebody uninstalls them - they simply stop being able to authenticate.
Deleting your account (under Settings > Security) erases any organization you solely own. It is refused if that would strand other members or an MSP customer workspace, so a customer's workspace cannot disappear as a side effect of somebody closing their personal account.