- Members: users who have been invited to the org
- Scope: projects, workspaces, and services belong to an org
- Access: org admins can invite/remove members and manage roles
- Your code and data stay within the workspace — they don’t leave your environment
- Grant/revoke access via org membership; no device copies to manage

