Skip to main content
Pinecone Docs

Search documentation

Type to search this documentation.

On this pageOverview

Organizations overview

Learn how Pinecone organizations group projects under shared billing, and how organization owners, members, and roles control access and permissions.

A Pinecone organization is a set of projects that use the same billing. Organizations allow one or more users to control billing and project permissions for all of the projects belonging to the organization. Each project belongs to an organization.

Each organization contains one or more projects that share the same organization owners and billing settings. Each project belongs to exactly one organization. If you need to move a project from one organization to another, contact Support.

All of the projects in an organization share the same billing method and settings. The billing settings for the organization are controlled by the organization owners.

Organization owners can update the billing contact information, update the payment method, and view and download invoices using the Pinecone console.

Organization owners can manage access to their organizations and projects by assigning roles to organization members and service accounts. A role determines the permissions that a principal (a user, service account, or API key) has within Pinecone. The organization roles are as follows:

  • Organization owner (OrgOwner): Full control over the organization, including billing, members, service accounts, security, and every project. Inherits owner access to all projects in the organization.

  • Organization manager (OrgManager): Can view organization details and create projects. Organization managers can't manage billing, members, service accounts, or organization settings.

  • Organization member (OrgMember): Can view organization details and access the projects they're added to. Organization members can't create projects or manage organization settings. To grant project access, add the member to one or more projects and assign a project role; see Manage project members.

  • Billing admin (OrgBillingAdmin): Can view organization details and manage billing, subscriptions, and usage. Billing admins can't manage members or organization settings, and they can't manage projects unless they're also project owners.

The following table summarizes the permissions for each organization role:

Permission Owner Manager Member Billing admin
View account details ✓ ✓ ✓ ✓
Create projects ✓ ✓
View billing and usage details ✓ ✓
Manage billing details ✓ ✓
Invite and remove organization members ✓
Update organization member roles ✓
Manage service accounts ✓
Configure single sign-on (SSO) ✓
Configure audit logs ✓
Update organization name ✓
Delete the organization ✓

SSO allows organizations to manage their teams' access to Pinecone through their identity management solution. Once your integration is configured, you can specify a default role for teammates when they sign up.

For more information, see Configure single sign-on.

Service accounts enable programmatic access to Pinecone's Admin API, which can be used to create and manage projects and API keys.

Use service accounts to automate infrastructure management and integrate Pinecone into your deployment workflows, rather than through manual actions in the Pinecone console. Service accounts use the organization roles and project role for permissioning, and provide a secure and auditable way to handle programmatic access.

Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu