> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.rightbrain.ai/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.rightbrain.ai/_mcp/server.

# Projects & organizations

> Organizations contain Projects; Projects contain every Rightbrain resource. Roles control access, and API paths carry org and project IDs.

Every Rightbrain resource lives in a hierarchy:

```mermaid
graph TD
  O[Organization] --> P[Project]
  P --> T[Tasks]
  P --> A[Agents]
  P --> S[Skills]
  P --> C[Collections]
  P --> N[Connections]
  P --> TR[Triggers]
```

An **Organization** owns billing and membership and is the root of ownership. A **Project** contains the actual resources — [Tasks](/docs/concepts/tasks), [Agents](/docs/concepts/agents), [Skills](/docs/concepts/skills), [Collections](/docs/concepts/collections), [Connections](/docs/concepts/connections), and [Triggers](/docs/concepts/triggers-and-runs). All access control is anchored at the Project.

## When this matters

Every API path carries both IDs, and every permission check resolves against a Project. So before you build anything you need to know: which organization, which project. Use projects to separate teams, clients, or environments — one project per client is a common pattern.

## Roles and permissions

Authorization is relationship-based. Membership grants roles, and roles grant permissions on resources.

At the **organization** level, members are broadly `owner`, `editor`, or `viewer` (plus domain- and email-allowlist invite rules).

At the **project** level, roles are fine-grained. Beyond owner/editor/viewer, a project defines targeted roles such as:

* `task_creator` / `task_runner` — create Tasks vs. run them.
* `data_creator` / `data_editor` / `data_viewer` — manage knowledge and documents.
* creator roles per resource type — `create_skill`, `create_collection`, `create_task_agent`, `create_project_integration`, and the MCP-server creator roles.
* run permissions — `run_task` and `run_task_agent`.

IAM-enabled resources also expose their own members endpoints (`.../{id}/iam/...`) so you can grant access on a single Task, agent, Skill, Collection, or connection rather than the whole project.

## API keys

An **API key** is a machine credential created and managed under a project. It authenticates as its owning user, with access evaluated against the requested resource. The project where a key is created is not an access-isolation boundary. Keys are stored encrypted, and revoking a key immediately invalidates its token.

All Rightbrain authentication uses `Authorization: Bearer <token>` — an API key is one kind of bearer token. See [Authentication](/docs/api/authentication) for the full auth model (user sessions, OAuth2 client-credentials and authorization-code, task access tokens, and public tasks).

## Where org\_id and project\_id come from

Resource endpoints are shaped:

```
/api/v1/org/{org_id}/project/{project_id}/<resource>
```

The `org_id` and `project_id` come from the **URL path**, not from your token — the same key can address any project you have permission for by changing the path. Both IDs are returned by the Organization and Project list endpoints.

## Minimal example

List the projects in an organization, then list the Tasks in one.

**`List projects`**

```bash title="List projects"
curl https://app.rightbrain.ai/api/v1/org/{org_id}/project \
  -H "Authorization: Bearer $RB_TOKEN"
```

**`List tasks in a project`**

```bash title="List tasks in a project"
curl https://app.rightbrain.ai/api/v1/org/{org_id}/project/{project_id}/task \
  -H "Authorization: Bearer $RB_TOKEN"
```

## Related

#### [Authentication](/docs/api/authentication)

Bearer tokens, API keys, OAuth2, and public tasks.

#### [Observability & audit](/docs/production/observability)

Audit events and access history.

#### [Model governance](/docs/production/model-governance)

Restrict model availability at Organization and Project scope.

#### [Agents](/docs/concepts/agents)

The resources a project holds.

#### [API Reference — Platform](/api-reference/api-reference/platform)

Organizations, Projects, Users, and API Keys.