Manage your organization
Share a workspace and its norms with colleagues by inviting them to your organization.
The number of seats is set by your space's plan. An invitation beyond it is refused when it is sent, not when the person accepts. For more seats, write to us from the account menu › Écrire à Stratta (write to Stratta).
In Stratta, a workspace is an organization. Everyone in the same organization shares its documents and can use them through their own agent. This is how an organization gives its whole team access to the norms, laws and frameworks it has deposited.
Your organization
When you sign up, you get a space and become its owner. From stratta.ch the owner and administrators can rename the space, invite members and manage invitations.
Invite a teammate
Open your organization settings
Sign in and go to the Organization page in your dashboard.
Send an invitation
Enter your colleague's email and send the invite. They receive an email with a secure link that is valid for 7 days. To invite several people at once, paste up to twenty addresses separated by commas or line breaks: each one gets its own link, and the ones that could not be sent are listed.
They accept
The invitee clicks the link. If they don't have an account yet, they sign up first (the invitation is preserved through sign-up) and are then added to your organization.
When someone accepts an invitation, they join your workspace rather than getting an isolated one. If they had just signed up, their empty personal workspace is cleaned up automatically.
Manage members and invitations
The owner and the admins manage the people of the space from the Organization page.
- A pending invitation shows when it was sent and when it expires, or "expired". Resend sends a new link, valid for seven days; the old one stops working. At least a minute separates two sends. Cancel withdraws the invitation.
- A person's menu makes them an admin or a member, or removes them from the space. They lose access at once, their API keys are revoked, and they get an email.
- The history, folded under the invitations, shows those of the last thirty days that were accepted or cancelled.
The owner cannot be removed, and nobody removes themselves or changes their own role.
Transfer the space
The owner can hand the space to an admin: the person's menu, Transfer the space to them, then type the space's name to confirm. They become the owner, and the former owner stays an admin. To transfer to a member, make them an admin first.
The space's journal
The owner and the admins read, at the bottom of the Organization page, what was done to the space and by whom: invitations sent, resent or cancelled, arrivals and departures, roles, transfers, access keys created and revoked, the AI key, plan changes, the space's name. A line stays there a year.
Export the space
Prepare the archive gathers everything the space holds into a ZIP file: members, norms and their clauses, dossiers with their questions, entries and pieces, deliverables, methods, sites and their boreholes, and the journal. Secrets (keys, invitation tokens) are never in it. The archive can be downloaded for seven days, by an owner or an admin; a new one can be prepared an hour after the last. Files stop at 64 MB: past that they are listed in the archive and sent on request to hello@stratta.ch.
Leave or delete the space
At the bottom of the Organization page:
- Leave the space: any member except the owner. You lose access to its norms and dossiers, your API keys for this space are revoked, and what you wrote there stays in the space. The owner is told.
- Delete the space: the owner only, typing the space's name. Its norms, dossiers, pieces, deliverables and sites are erased, its share links stop answering at once and its subscription ends. Members are told by email.
If the owner deletes their account, a shared space goes to its earliest admin (or, failing that, its earliest member), who is told by email. The subscription, paid by the former owner, ends at the end of the current period. A space they were alone in is erased.
What members share
Everyone in the organization can:
- Query the norms the organization has ingested, from their own Claude.
- Create and manage their own API keys.
- Ingest additional norms (which become available to the whole organization).
API keys are personal. Each member uses their own. See Manage API keys.
Belonging to several organizations
If you are a member of more than one organization, a switcher appears at the top of the sidebar. It does not show up while there is nothing to choose.
Switching changes everything that depends on the organization: dashboard, dossiers, quotas, billing, invitations, and the norms your agent can read.
Two things deliberately do not follow the switcher. An API key stays bound to the organization it was created in. And a connected agent keeps the organization you picked when you authorised it, and you can change it from Connected agents. An agent configured once should not start answering from a different corpus because you changed tabs.
Signing in through your company directory
On request, your people can sign in with the account they already have (Microsoft Entra ID, Google Workspace, or any OpenID Connect provider) instead of one more password.
The three states on the Organization page
The organization's owner sees one of three states there, and only the owner.
- Not set up. Your people sign in with a password. A "Request enterprise sign-in" button opens a pre-filled message to our address.
- To verify. We have bound your domain; the page shows the TXT record to publish and the button that runs the check.
- Active. The page names the domain, the provider, the role new arrivals get, and says whether a password is still allowed.
How it goes:
On Microsoft 365 there is nothing to create
The common case, and the short one: your IT team registers no application and sends us no secret.
You prove the domain is yours
We bind your domain to your organization, and the Organization page shows a TXT record to publish at
_stratta-sso.<your-domain>. Nothing is switched on before that proof.Your administrator consents, once
We give you a Microsoft consent link. Your administrator opens it, accepts, and that is the end of it. Nothing expires, unlike an application secret that would need renewing every two years.
Your people sign in
On the sign-in screen, typing an address on your domain brings up the Microsoft button. The first sign-in creates the account and attaches it to your organization with the role you chose.
We only accept a token if it comes from the Microsoft directory that actually owns your domain. We resolve that with Microsoft ourselves, and Microsoft only admits a domain into a directory after a DNS proof. Nobody can claim to be one of your people from another directory.
With another provider, or your own application
Google Workspace, or a Microsoft directory you would rather keep separate:
You register an OIDC application
On your side, with redirect URI
https://stratta.ch/api/auth/oauth2/callback/<your-provider-id>, then send us its client id and secret.You prove the domain, your people sign in
As above.
A Microsoft application secret expires (two years at most). When it does, sign-in stops dead. That is why we recommend the first path where possible.
On request we can refuse passwords on your domain: sign-in, sign-up and password reset all become impossible except through your directory. That is what makes an account closed on your side an account closed here, and it is also what stops you coming back in with a password, so ask for it knowingly.
There is no directory synchronisation (SCIM). Removing someone from the organization in Stratta cuts their access to the corpus on the very next call, including for an agent that is already connected.