# Organization Memberships

> How Corbis organization billing, seats, invitations, SSO and SCIM, roster privacy, org policies, governance exports, and the personal-plan handoff work.

Corbis organizations let one admin buy a team subscription, invite users by email, and manage access, policy, and billing from a single account.

This guide explains what happens when a team is created, how seats and credits are counted, how invitations are accepted or declined, how single sign-on and directory provisioning work, and what happens if an invited user already has a personal subscription.

For current plan details, see [Plans & Pricing](/docs/plans-and-pricing).

---

## At a Glance

| Topic | How Corbis works |
|------|------|
| Billing owner | The organization admin manages the organization subscription |
| Supported organization tiers | Academic organizations use the Academic tier; corporate organizations use Basic or Pro |
| Billing cadence | Monthly or annual. Admins can switch cadence in Settings when the organization pays by card |
| Seat capacity | Paid seats plus any complimentary seats granted by Agentic Assets. Between 1 and 250 total |
| What uses a seat | The admin, each active member, and each outstanding invitation that has been sent but not yet accepted or expired |
| What does not use a seat | Declined invitations and removed members do not count toward seats |
| Invite expiration | Invitations expire after 7 days if they are not accepted |
| How you join | The email link opens **Settings → Team** and shows a **review** step; joining requires **explicit confirmation**. Opening the link does not join you automatically |
| Declining | You can decline an invitation in Settings; that **frees a seat** for the team |
| Who can accept | You must sign in with the same email address that was invited |
| Email requirements | You must have a verified email before accepting |
| Chat credits | Members draw from the shared organization credit pool when one is set up |
| Workflow runs, projects, files | Counted per member, not pooled |
| Member list privacy | Admins can hide the full member list from non-admins; members then see only themselves on the roster |
| Organization policies | Admins can force zero data retention and force stable output for the whole team |
| Governance | Admins can export a redacted AI-action audit trail and an aggregate research activity report |
| Directory integration | SAML single sign-on and SCIM user provisioning are available; connection setup is handled by Agentic Assets |
| Admin handoff | An admin can transfer the admin role to another active member |
| If you already have a paid personal plan | Corbis asks for confirmation, then accepts the invite and schedules the personal plan to cancel at period end |
| During the overlap | You keep the higher of the personal tier and organization tier until the personal plan ends |
| If org access ends early | Corbis attempts to restore the frozen personal balance and workflow state |

---

## For Organization Admins

The organization admin is the billing owner for the team subscription. One account can administer up to **5** organizations.

In practice, the admin can:

- create the organization and start billing
- change the plan, the seat count, and the billing cadence
- cancel or resume the organization subscription
- invite, resend, dismiss, and remove members
- control whether non-admins see the full member list
- set organization-wide AI policies (zero data retention, stable output)
- export governance and research activity reports
- manage the SCIM provisioning token
- transfer the admin role to another active member

Two important rules:

- an organization must have an **active** subscription before invitations can be sent
- organization usage is blocked when the organization is not in an eligible billing state

Team management lives at **Settings → Team**. Billing details for your own account live at **Settings → Billing**.

### Plans and billing

Academic organizations are billed on the **Academic** tier. Corporate organizations are billed on **Basic** or **Pro**. An organization cannot switch between the academic and corporate tier families in-app.

Admins have two ways to change billing:

- **In Settings → Team**, change the plan and the paid seat count directly, then choose **Save changes**. Reducing seats asks for confirmation first.
- **Open Stripe Billing Portal** for payment methods, invoices, and receipts.

A **Switch to annual billing** or **Switch to monthly billing** button appears next to the portal link when the organization pays by card and Corbis can read the current cadence. Changing cadence goes through that dedicated control rather than the plan selector, because a plan change and a cadence change are handled separately. Organizations billed by invoice (for example NET-30) cannot change plans or cadence through the hosted portal; those admins use the in-app controls instead.

Credit allowances are **monthly regardless of billing cadence**. An annual organization is refilled every month for twelve months rather than receiving a year of credits up front.

Admins can also **Cancel subscription** from Settings → Team. Cancelling schedules the subscription to end at the end of the paid period, and a **Resume subscription** button appears until that date passes.

### How seats are counted

Total capacity is the **paid seat count plus any complimentary seats**. Complimentary seats are granted by Agentic Assets and are not billed through Stripe; paid seats are the quantity on the Stripe subscription. Total capacity is between 1 and 250.

These count as occupied seats:

- the admin account
- every active member
- every **outstanding invitation** (email sent, not yet accepted, not yet expired)

Sending an invitation reserves a seat for that person until they join, you remove the invitation, it expires, or they **decline**.

**Declined** invitations do **not** use a seat. Someone who declined may still appear on your team list so you can send a new invitation to the same address when you are ready. **Expired** invitations stop holding seats; Corbis cleans them up nightly, and you can invite that person again.

To reduce abuse, sending invitations is **rate-limited per organization** (up to **20** new invite or resend attempts per hour in the current product). If you hit the limit, wait a short time and try again.

### How invitations behave

Invitations are sent by email and expire after **7 days**.

If an invitation is not accepted in time:

- it stops holding a seat once it expires
- it will not work as a valid join link after that
- you can send a new invitation to the same email when you have room and the organization subscription is active

If someone **declines**:

- they do not join, and their seat is freed
- the declined row stays visible so you can resend the invitation or remove the row from the list

### Member list visibility

By default, members can see the full team roster. The admin can turn off **Show member list to team** so that **non-admin members only see their own row**. Admins still see the full list. Use this when you want to limit visibility of who else is on the team.

### Transferring the admin role

An admin can hand off billing and team ownership without contacting support. In the member list, choose **Make organization admin** on an active member and confirm **Transfer admin role?**.

The transfer takes effect immediately. The previous admin keeps their seat and membership but loses billing and team management access, so make sure the new admin is the right person before confirming. If another change to the organization lands at the same time, the transfer is refused and you can retry.

### Organization AI policies

Two organization-wide settings in **Settings → Team** apply to every active member working in that organization context.

#### Force zero data retention

When **Force zero data retention** is on, covered AI requests made while the organization is active force request-level zero data retention through Vercel AI Gateway, which asks Gateway to route only to compliant providers and fallbacks. This applies to active team members under that organization context even if the workspace-level default is off.

Two effects members will notice:

- **The model list gets shorter.** Only models that support Gateway zero data retention and disallow prompt training remain selectable.
- **Some capabilities are blocked.** Features that must run directly on a model provider outside AI Gateway are refused rather than sent, so the setting cannot be bypassed. If the policy leaves no eligible model at all, Corbis fails closed and asks the member to contact their administrator instead of quietly falling back.

Turning it off means the organization stops forcing the setting and covered requests use the app default. This setting does not verify requests made outside AI Gateway.

#### Force stable output

When **Force stable output** is on, Corbis pins generation to its most repeatable setting for every member request in that organization, regardless of each member's own composer setting. Use this when your team needs answers to be as reproducible as possible across runs. Members can still see that stable output was applied on each response.

### Governance and reporting

Admins can export two organization reports from **Settings → Team**. Both cover a date window of up to **180 days** and export as **CSV** or **JSON**.

- **AI-action audit browser.** A per-event record of chat requests and tool executions by active members. It is **redacted by design**: identifiers are replaced with stable references, and prompt text, message content, tool inputs and outputs, and raw error text are never included. It does include model, reasoning level, token counts, credit cost, duration, and success or failure.
- **Research activity report.** Aggregate metrics only, such as workflow runs by workflow and status and overall tool activity. It contains no raw user, chat, project, or document identifiers.

Both reports are scoped to each member's organization membership period, so they do not reach back before someone joined.

### Single sign-on and SCIM

Corbis accounts can sign in with email and password, with Google, LinkedIn, or GitHub, or through your organization's identity provider. Organizations that need centralized control can add **SAML single sign-on** and **SCIM user provisioning**.

**Setting up a connection is handled by the Agentic Assets team, not self-serve.** Contact us to register your identity provider and the email domains that should route to it. Corbis supports service-provider-initiated SAML, which means sign-in starts from Corbis. A tile in your identity provider's dashboard should point at the Corbis SSO entry point rather than sending an unsolicited assertion.

Each email domain your provider asserts must be registered on the connection. If your provider asserts a subdomain (for example `warrington.university.edu` when users type `university.edu`), that subdomain needs to be registered too, or sign-in is refused.

Once configured, an organization is set to one of two enforcement modes:

- **Optional.** Members can sign in with SSO or with any other supported method.
- **Required.** Members must have completed an SSO sign-in tied to your provider to hold organization access. Enforcement applies when Corbis resolves organization access: accepting an invitation, admin actions, and ongoing membership all require it. It does not disable other sign-in methods for the account itself, so a member who signs in another way can still reach their personal workspace but will be blocked from organization access until they complete one SSO sign-in.

**SCIM** lets your identity provider create, update, and deactivate Corbis members automatically. Admins manage it in **Settings → Team**: copy the SCIM base URL, generate or rotate a bearer token (shown once), and revoke it when needed. The organization must be active to issue a token.

Current scope, stated plainly:

- **User provisioning and deprovisioning are supported**, including the common identity-provider patterns for deactivating a user.
- **Groups are read-only.** Corbis exposes membership groups for inspection but does not accept group pushes, so provisioning driven purely by group membership is not supported yet.
- **The organization admin cannot be removed through SCIM.** Transfer the admin role first.
- When SCIM deactivates a member, their organization access and organization-tier entitlement end immediately, and if they had converted from a personal subscription Corbis attempts the same personal-plan restore described below.

---

## For Invited Users

### Finding your invitations

Pending team invitations appear in several places:

- a badge on the **Team** tab in **Settings**
- an indicator on your account avatar in the sidebar
- a one-time prompt after you sign in, which links to **Settings → Team**

If you lose the email, open **Settings → Team** to review and respond. You do not need a paid plan to see and respond to a pending invitation.

### Requirements to accept

To accept successfully, all of the following must be true:

- you are signed in
- your email is verified
- your signed-in email matches the invited email address
- the invitation is still valid and not expired
- the organization subscription is active
- if the organization requires SSO, you have signed in through that provider

If any of those checks fail, you cannot accept until it is fixed.

### How accepting works (preview, then confirm)

Invitation links take you to **Settings → Team** and open a **review** dialog. Corbis loads a preview of what joining means: the organization name, plan context, and, if you have a personal subscription, what changes about your billing. **Nothing is finalized until you confirm.** Simply opening the link does not add you to the team.

#### If you do not have a paid personal subscription

1. Use the link in the email, or open **Settings → Team**.
2. Review the join preview and choose **Join Team**.
3. Corbis activates your organization membership and organization-based access.

#### If you already have a paid personal subscription

Corbis treats this as a transition, not an instant swap. The confirmation step is required, and the button reads **Join Team and End Personal Plan at Renewal**.

Before you confirm, the preview explains that:

- your personal subscription will be scheduled to end at the end of its current billing period
- your access during the overlap reflects whichever is higher, your personal plan or the organization plan
- your personal credit balance and workflow usage are frozen so they can potentially be restored if team access ends early

Corbis does **not** cancel your personal subscription the moment you confirm. It is scheduled for period end as described.

This confirmation also applies if your personal subscription is on a trial, past due, or unpaid, not only when it is fully paid and active.

#### If your organization uses SSO

Some organizations require **single sign-on**. You must complete SSO with an identity that satisfies the organization's policy **before** acceptance can finish. If SSO is required and your session does not satisfy it, acceptance stays blocked until you sign in through that provider. Your admin or IT team can confirm the expected provider.

#### If something blocks acceptance

| What you see | What it means | What to do |
|------|------|------|
| Single sign-on is required | The organization enforces SSO and your session does not satisfy it | Sign in through your organization's identity provider, then accept again |
| Email verification required | Your Corbis email is not confirmed yet | Finish verifying your email, then return to **Settings → Team** |
| The organization plan changed | The plan changed after you opened the preview | Reopen **Settings → Team** and confirm again so you join under the current plan |
| Confirmation required | You have a paid personal subscription and have not confirmed the handoff | Reopen the invitation and confirm the personal-plan consequences |
| Already a member | The membership is already active | Refresh Settings; no further action is needed |
| Invitation not found or expired | Invitations stop working after 7 days | Ask an admin to send a new one |
| A membership change is in progress | Another billing or membership update is still settling | Wait a moment and try again |
| Billing requires administrator repair | A billing step did not complete cleanly | Contact your organization admin or Corbis support; this needs a person to resolve |

### Declining an invitation

You can **decline** a pending invitation from **Settings → Team**. If you decline:

- you are not added to the organization
- **you do not use a seat**, and the team can invite you again later if they choose

---

## Personal Plan to Organization Plan Transition

This is the most nuanced part of organization billing, and Corbis handles it explicitly when you confirm joining from a paid personal account.

### What happens at acceptance time

Corbis re-checks your live subscription state at the moment you confirm rather than trusting the earlier preview. If the two disagree, acceptance stops and asks you to review again rather than committing a change it cannot complete.

When a paid personal user confirms joining an organization:

- Corbis records the team membership
- Corbis snapshots your personal usage state
- Corbis schedules the personal subscription to cancel at period end
- Corbis records a transition state so the system can finish or restore the handoff correctly later

The personal snapshot includes:

- remaining personal credits
- the personal reset date
- workflow usage state

### What access do you get during the overlap?

Until the personal subscription actually ends, you keep the **higher** tier of:

- the personal subscription tier
- the organization tier

That means:

- if the personal tier is higher, you keep that higher tier until the personal period ends
- if the organization tier is higher, the organization tier can take effect right away
- if both tiers are the same, access stays the same while billing shifts over time

Chat usage during the overlap draws from the **organization credit pool** when the organization has one set up. Your frozen personal balance is held for a possible restore rather than spent.

### What happens after the personal subscription ends?

Once the personal billing period ends, you continue on the organization tier only.

### Ending a personal plan early while you are a member

If you are already an active member and you are still paying for a personal plan alongside your seat, **Settings → Billing** offers an explicit action to end the personal plan at the end of its paid term while keeping your organization seat.

This action is available to any active member, including the person who created the organization. It confirms the exact personal subscription it is ending, it never touches your membership or seat, and your paid personal term runs to its normal end date.

### What happens if organization access ends before then?

If you lose organization access before the original personal billing period would have ended, Corbis attempts to restore the frozen personal state, so a personal plan you already paid for is not lost.

Restore is **best effort, not guaranteed**. If the restore cannot be completed cleanly, Corbis marks the membership as needing repair and alerts the team rather than silently leaving the account in a wrong state. Recovery in that case is handled by a person, not automatically, so contact your admin or Corbis support if you see a repair message.

---

## Billing, Access, and Usage

In Corbis, these are related, but they are not always the same thing.

| Concept | What it means |
|------|------|
| Billing source | Who is currently treated as the payer: personal, organization, or free |
| Effective tier | The access level you can actually use right now |
| Usage source | Whether usage is currently coming from the organization pool or the personal account |

For most organization members:

- billing is organization-based
- effective access is the organization tier
- usage comes from the organization pool

For users in the personal-to-organization overlap window:

- billing and effective access may not match yet
- you may still see personal billing details while already holding organization membership
- Corbis uses the higher tier during the overlap on purpose

### What is shared and what is per member

| Resource | Shared or per member |
|------|------|
| Chat credits | **Shared** organization pool when the organization has one, with a monthly reset |
| Monthly workflow runs | Per member, based on that member's effective tier |
| Projects and project files | Per member |
| MCP connections and API keys | Per member |

Only the admin sees the organization credit pool balance, on the Team tab. Every member sees their own usage on the Billing tab, which reflects the organization pool when the organization is paying.

---

## If Billing Changes or Access Ends

### If the organization is waiting on payment

The organization does not become usable until billing is active. Organizations still waiting on payment do not get team access until payment is confirmed, and invitations cannot be sent or accepted in that state.

### If the organization becomes past due

If an active organization later has a payment failure, Corbis allows a short grace window while payment is retried. In the current implementation, that grace period is up to **7 days**.

### If the organization is cancelled mid-cycle

If the organization is cancelled but still has paid time remaining, members keep access through the paid-through date. Corbis then removes organization access after that grace window ends.

### If the organization is suspended

A suspended organization does not grant access and cannot add members. Contact Corbis support to resolve it.

### If an admin removes a member

When a member is removed:

- the organization membership is removed
- organization-tier access tied to that membership is turned off
- if the user joined from a paid personal plan and there is still restorable personal time left, Corbis attempts to restore that personal state

The same applies when a member is deactivated through SCIM.

---

## Multi-Organization Membership

Yes, you can belong to more than one organization.

Corbis uses a preferred **active organization** so the app can decide which organization context to use for organization-based billing, usage, and policy.

If you belong to multiple organizations, check which one is active before doing work that should count against team usage. Organization policies such as forced zero data retention and forced stable output follow the active organization, so switching context can change which models you see.

Separately, one account can administer up to **5** organizations.

---

## Common Questions

### Does the email link join me automatically?

No. The link opens **Settings → Team** and a review dialog. You must confirm to join.

### Can I decline an invitation?

Yes. In **Settings → Team**, you can decline. You will not be added to the team.

### Does declining free a seat?

Yes. A declined invitation does not count toward the team's seats.

### Does the admin use a seat?

Yes. The admin is an active organization member and counts toward the seat total.

### Do outstanding invitations take up seats?

Yes. A non-expired invitation that has been sent but not accepted reserves a seat until someone joins, you remove it, it expires, or the invitee declines.

### Can I accept an invitation with a different email than the one that was invited?

No. The acceptance flow checks the invited email address directly.

### Why don't I see everyone on the member list?

Your organization's admin may have turned off the full roster for non-admins. In that case you see only your own row. Admins still see the full list.

### Why did my model list get shorter after I joined a team?

Your organization may have turned on forced zero data retention, which limits selection to models that meet that policy.

### Do I lose my personal subscription immediately when I join a team?

No. If you already have a paid personal plan, Corbis schedules it to cancel at the end of the current billing period after you confirm joining.

### What if my personal plan is better than the organization plan?

You keep the higher personal tier until the personal billing period ends. After that, you continue on the organization tier.

### What if the organization removes me before my personal billing period would have ended?

Corbis attempts to restore the frozen personal state from when you joined the organization. If that restore cannot complete, Corbis flags the account for repair rather than leaving it in a wrong state.

### How can members sign in?

With email and password, with Google, LinkedIn, or GitHub, or through your organization's identity provider if SSO is configured.

### Can our organization use SAML SSO or SCIM?

Yes. Both are supported today. Connection setup is handled by the Agentic Assets team rather than a self-serve configuration screen, so contact us to get started. Admins manage the SCIM token themselves once the connection exists.

### Can an admin hand the organization to someone else?

Yes. An admin can transfer the admin role to any active member from **Settings → Team**. The change takes effect immediately.

### Can we pay annually?

Yes. Organizations can be billed monthly or annually, and card-paying admins can switch cadence from **Settings → Team**.

---

## Best Practices

For admins:

- confirm the organization subscription is active before inviting people
- remember that outstanding invitations reserve seats until they are accepted, expire, or are declined
- follow up on declined or expired invitations by sending a new invitation when appropriate
- use member list visibility settings if your policy requires limiting who can see the full roster
- decide on zero data retention and stable output before onboarding the team, since both change what members can do
- transfer the admin role before removing an admin's access or offboarding them
- warn users in advance if joining the team will change a personal paid plan at renewal

For invited users:

- sign in with the exact email that was invited
- verify your email first
- if your organization uses SSO, sign in through that provider before accepting
- use **Settings → Team** if you need to find or respond to invitations without the email
- read the preview and confirmation step carefully, especially if you already have a personal subscription
- if you belong to multiple teams, confirm which organization is active before doing team-billed work