Admin: Your organization
How a DraftMesh organization is created from your WorkOS organization, the flat Admin and Member roles, and what an admin can do that a member cannot.
DraftMesh’s Administration console is where your organization’s admins can see the whole account at once: what has happened, who can reach which documents, who has been invited, and which agents are registered.
It lives under ⚙ Settings → Administration…, and it is part of the signed-in cloud product. A DraftMesh running locally on your own machine has no organization and no console.
Where your organization comes from
DraftMesh does not have its own directory of companies. Your organization is your WorkOS organization — the same one your identity provider signs people into — paired with a DraftMesh account that every workspace, share, agent, and audit record then belongs to.
That pairing is set up deliberately, not on first sign-in. An organization DraftMesh has not been set up for is refused rather than quietly created, which is what keeps one company’s records from ever landing in another’s. You ask for one with ⚙ Settings → Create an organization…; a person on the DraftMesh team reviews the request, and once it is granted you are its first admin.
Signing in without an organization is different: you get a personal account, created for you on the spot. It is yours and nobody else is in it. Sharing, agents and the console all belong to an organization, though, so a personal account has none of them — ask for one when you want to bring colleagues in.
Admins and members
There are exactly two roles, and they are flat: Admin and Member. Every admin holds the same authority as every other — there is no senior admin, and no per-section permission to hand out.
The person the organization was set up for is its first admin. Everyone else who signs in afterwards arrives as a member, until an admin says otherwise or they were invited as an admin.
Admins change that in Administration… → Overview, in the Members (as observed) table: each person’s row carries a Role of Admin or Member, and a Make admin / Remove admin button beside it. Two things the button refuses, and says why rather than failing silently:
- An organization can never reach zero admins. Once the member list has finished loading, the control on the last remaining admin is disabled and reads “This is the organization’s only admin. Promote someone else before removing their admin access.” — and whether or not the console has got that far, the server refuses to remove the last admin.
- Only people can hold a role. Agents and service accounts are listed but never promotable.
A demotion bites immediately: the next thing that person asks DraftMesh for is answered as a member, without waiting for them to sign out.
You can also set the role up front — an invitation sent from the Members section carries Member or Admin, applied when that person first signs in.
Your account also records an owner, separately from these roles. It is the billing and accountability contact, and it confers no extra power in the product — an owner who is not an admin sees no console. There is no screen for changing who the owner is, so if that needs to move, ask DraftMesh. Admin authority itself is not stuck: promote and demote as the team changes.
Inviting someone in
Administration… → Members → Invite someone… takes an Email address and a Role (Member or Admin, defaulting to Member), and Send invitation puts the invitation out through your identity provider — this one always emails the person, where a document share does only when the host can send email (its Share panel says which happened).
The role you pick is applied when they first sign in, not before. Until they accept, the invitation sits in the table below with a state of Pending, Accepted, Revoked, or Expired, and a pending one can be withdrawn with Revoke.
Inviting the same address twice is safe and honest about itself: you are told the person “already has an invitation outstanding — nothing new was sent”, or that they are “already a member of this organization”, rather than quietly sending a second email.
An invitation is about getting into the organization. It grants no documents — sharing is a separate act, described in Admin: Access & sharing.
Seats. If your organization has a seat limit and every seat is taken, an invitation is refused and the console says so in as many words — “this organization has no seats left (10 of 10 in use)”. A seat is a person DraftMesh has seen in the organization; an invitation you have sent does not use one until that person signs in, so it is possible to send more invitations than you have seats and end up over the limit, which the Seats tile on Overview shows. Plans and seat limits are set by the DraftMesh team, not from this console — raising one is a conversation, not a button.
What an admin can do that a member cannot
| Admin | Member | |
|---|---|---|
| ⚙ Settings → Administration… | Shown | Not shown |
| Share a document, or revoke a share | Yes | No |
| Create or revoke a guest link | Yes | No |
| Register, rotate, or revoke an agent | Yes | No |
| Invite someone to the organization | Yes | No |
| Make someone an admin, or remove admin | Yes | No |
| Read the organization’s audit log | Yes | No |
| Read and write documents they have access to | Yes | Yes |
| Read and write every document in the organization | Yes | No |
An admin’s reach is not limited to the documents shared with them. Admin authority carries edit on every document in the organization, with no grant needed — promoting someone hands them that.
A member does not see a greyed-out Administration entry, or one that fails when clicked. They see nothing — the menu simply does not have it. That is deliberate: a disabled control tells someone a door exists and invites them to rattle it.
Sharing and agent management are admin-only whatever else somebody holds. Being granted edit on a document never confers the ability to re-share it, register an agent, or read anyone else’s activity.
The five sections
- Overview — your organization’s totals at a glance: People & agents, Active sessions, Workspaces, Active agents, Document shares, Live guest links, and Seats — how many people DraftMesh has seen in the organization against the seat limit on its plan (a person is a seat; agents and service accounts are not), with the plan named underneath. Two of the tiles say what they leave out, on the tile: Active sessions counts the credentials DraftMesh issued and not browser sign-ins, and Active agents is the live count with the registry total (revoked included) beside it. A Single sign-on card sits below the totals: each connection your WorkOS organization has, with its state in WorkOS’s own words, and Manage in WorkOS to open the Admin Portal in a new tab. If DraftMesh cannot read it, the card says so rather than showing an empty list. Below that, Members (as observed) — the people and agents DraftMesh has actually seen, with their role, the promote/demote control, and a Sessions view of the device and agent credentials issued to each, with a per-device Revoke — plus, below it, Members homed in another organization: people who hold shares here but whose DraftMesh account lives elsewhere, listed by account id with the same connector Block control, because they cannot appear in the list above. And every workspace in the account.
- Members — the invitations this organization has outstanding: who has been asked in, at what role, and whether they have accepted yet.
- Audit log — every recorded action in the organization, filterable by action, person, and date, with a CSV export.
- Access review — everything shared across every workspace, in one list, with a Revoke on each row and a CSV export.
- Agents — the registered agents, where their work is delivered, the standing rules that wake them, and what happened to each delivery. What an agent can reach is its document grants, and those are listed under Access review, not here.
Overview and Members answer different questions, and the console says so on the page. Overview is a record of who has used DraftMesh; Members is a record of who has been asked in. Neither is a directory of your organization — DraftMesh does not read one.
Audit log, Access review and Agents each get a topic of their own in this guide; Overview and Members are covered above.
What is not here yet
The console is a governance surface, not a control panel for your identity provider. Identity-provider group membership and who is allowed to authenticate at all are configured in your WorkOS organization, not in DraftMesh — and so is single sign-on itself: Overview’s Single sign-on card reports your connections and hands you a link into WorkOS, but adding, editing or removing one happens there. (DraftMesh’s own Groups…, in ⚙ Settings, are targets for document grants and nothing more — they are not the identity provider’s groups and confer no console authority.) See Admin: Security posture FAQ for the full list of what does and does not live here.