Accounts and Teams
This surface is part of the Enterprise platform and is not included in DVARA Open Source. Without a licence an install has one account and one team; adding more needs a licence. See Limits without a licence.
DVARA governs AI traffic per workspace. Above the workspace sit a team and an account:
Account → Team → Workspace
- A workspace holds the API keys, governance settings, policies, budgets and audit trail.
- A team holds workspaces, typically
dev,stageandprodfor one group. Everyone in a team can switch between all of its workspaces in the Portal. - An account holds teams. It is the licensee on a self-managed install.
Team and account rate limits narrow every workspace underneath.
Until you add your own, every workspace is in the Default account and the Default team, which Flightdeck creates with the first workspace.
Who can use these pages
| Role | Accounts and Teams pages |
|---|---|
owner | Read and change |
policy-admin, billing-admin | Read |
| Workspace roles | No access. They see the result in the Portal workspace switcher. |
Create an account
- In the sidebar, open Access → Accounts.
- Under New account, enter a name and select Create account.
The list shows each account's status, how many teams and workspaces it has, and its rate limit. Rate limit opens the account-level limit form. Rename, Disable and Enable act on the row.
Create a team
- Open Access → Teams.
- Under New team, pick the account, enter a name, and select Create team.
The team's page opens. The Teams list shows each team with its account, status, workspace and member counts, and its team and account rate limits.
Move a workspace into a team
On a team's page, under Workspaces, pick a workspace in Move a workspace into this team and select Move here.
- The workspace keeps its keys, settings, policies, budgets and history. Only its team changes, so the team and account rate limits above it change too.
- People who were looking at it in the Portal and are not in the new team are switched to another of their workspaces.
- If one of them has no other workspace, the move is refused and nothing changes. The message names them: add them to the new team first, or give them another workspace.
Add people to a team
A person can be in more than one team. On a team's page, under Members, enter their email and select Add. They can now switch to any of that team's workspaces from the Portal switcher, where each workspace is shown as Team / workspace once they are in more than one team.
- The team of the workspace a person was created in is their home team, marked on the members list. It is not removed here.
- Remove takes a team away. If they were looking at one of its workspaces, the Portal switches them to a workspace of their home team.
- Platform users (
owner,policy-admin,billing-admin) reach every workspace by role and are not added to teams.
A person in team A cannot open a workspace in team B until they are added to B. A switch to any other workspace is refused with 403 and recorded as WORKSPACE_SWITCH_REFUSED.
Disable an account or a team
Disable is reversible and stops growth, not traffic:
- A disabled account takes no new team, and no workspace can be moved into its teams.
- A disabled team takes no new workspace and no new member.
- Their workspaces keep serving Gateway traffic. Enable undoes it.
- The Default account and team cannot be disabled, because a workspace created without a team joins them.
Limits without a licence
| No licence | Valid licence | Expired licence | |
|---|---|---|---|
| Accounts | 1 (Default); another is refused | Any number | Existing ones kept; no new one |
| Teams | 1 (Default); another is refused | Any number | Existing ones kept; no new one |
| Workspaces | 3 | Any number | Existing ones kept; a new one only while there are fewer than 3 |
Renaming, disabling, moving workspaces and adding people are never limited. A refused account or team shows the reason on the page and records ACCOUNT_LIMIT_REACHED or TEAM_LIMIT_REACHED in the audit log. A licence set on the Licence page lifts the limit at once, with no restart.
On DVARA Cloud, signup creates each account and its team, and these pages only read.
Audit events
| Event | When |
|---|---|
ACCOUNT_CREATED, ACCOUNT_RENAMED, ACCOUNT_DISABLED, ACCOUNT_ENABLED | An owner changes an account |
TEAM_CREATED, TEAM_RENAMED, TEAM_DISABLED, TEAM_ENABLED | An owner changes a team |
WORKSPACE_MOVED | A workspace moved to another team |
TEAM_MEMBER_ADDED, TEAM_MEMBER_REMOVED | Someone was added to or removed from a team |
ACCOUNT_LIMIT_REACHED, TEAM_LIMIT_REACHED | A new account or team was refused by the licence limit, from this page or a configuration import |
Configuration as code
A configuration export carries accounts, teams and team_members, so an import restores every team with its workspaces and people.