Admin: Your organization
How a DraftMesh organization is created from your WorkOS organization, the flat Admin and Member roles, and what an admin can do that a member cannot.
DraftMesh’s Administration console is where your organization’s admins can see the whole account at once: what has happened, who can reach which documents, who has been invited, and which agents are registered.
It lives under ⚙ Settings → Administration…, and it is part of the signed-in cloud product. A DraftMesh running locally on your own machine has no organization and no console.
Where your organization comes from
DraftMesh does not have its own directory of companies. Your organization is your WorkOS organization — the same one your identity provider signs people into. The first time someone signs in through it, DraftMesh creates the matching account behind the scenes and every workspace, share, agent, and audit record from then on belongs to it.
If you sign in without an organization, you get a personal account of your own, on the same rules: it is yours, and nobody else is in it.
Admins and members
There are exactly two roles, and they are flat: Admin and Member. Every admin holds the same authority as every other — there is no senior admin, and no per-section permission to hand out.
The first person from your organization to sign in to DraftMesh becomes its first admin. Everyone who signs in afterwards is a member until an admin says otherwise.
Admins change that in Administration… → Overview, in the Members (as observed) table: each person’s row carries a Role of Admin or Member, and a Make admin / Remove admin button beside it. Two things the button refuses, and says why rather than failing silently:
- An organization can never reach zero admins. On the last remaining admin the control is disabled and reads “This is the organization’s only admin. Promote someone else before removing their admin access.”
- Only people can hold a role. Agents and service accounts are listed but never promotable.
A demotion bites immediately: the next thing that person asks DraftMesh for is answered as a member, without waiting for them to sign out.
You can also set the role up front — an invitation sent from the Members section carries Member or Admin, applied when that person first signs in.
Your account also records an owner, separately from these roles. It is the billing and accountability contact, and it confers no extra power in the product — an owner who is not an admin sees no console. There is no screen for changing who the owner is, so if that needs to move, ask DraftMesh. Admin authority itself is not stuck: promote and demote as the team changes.
Inviting someone in
Administration… → Members → Invite someone… takes an Email address and a Role (Member or Admin, defaulting to Member), and Send invitation puts the invitation out through your identity provider — so unlike a document share, this one really does send the person an email.
The role you pick is applied when they first sign in, not before. Until they accept, the invitation sits in the table below with a state of Pending, Accepted, Revoked, or Expired, and a pending one can be withdrawn with Revoke.
Inviting the same address twice is safe and honest about itself: you are told the person “already has an invitation outstanding — nothing new was sent”, or that they are “already a member of this organization”, rather than quietly sending a second email.
An invitation is about getting into the organization. It grants no documents — sharing is still one document at a time, described in Admin: Access & sharing.
What an admin can do that a member cannot
| Admin | Member | |
|---|---|---|
| ⚙ Settings → Administration… | Shown | Not shown |
| Share a document, or revoke a share | Yes | No |
| Create or revoke a guest link | Yes | No |
| Register, rotate, or revoke an agent | Yes | No |
| Invite someone to the organization | Yes | No |
| Make someone an admin, or remove admin | Yes | No |
| Read the organization’s audit log | Yes | No |
| Read and write documents they have access to | Yes | Yes |
A member does not see a greyed-out Administration entry, or one that fails when clicked. They see nothing — the menu simply does not have it. That is deliberate: a disabled control tells someone a door exists and invites them to rattle it.
Sharing and agent management are admin-only whatever else somebody holds. Being granted edit on a document never confers the ability to re-share it, register an agent, or read anyone else’s activity.
The five sections
- Overview — your organization’s totals at a glance: People & agents, Active sessions, Workspaces, Registered agents, Document shares, and Live guest links. Below the totals, Members (as observed) — the people and agents DraftMesh has actually seen, with their role and the promote/demote control — and every workspace in the account.
- Members — the invitations this organization has outstanding: who has been asked in, at what role, and whether they have accepted yet.
- Audit log — every recorded action in the organization, filterable by action, person, and date, with a CSV export.
- Access review — everything shared across every workspace, in one list, with a Revoke on each row and a CSV export.
- Agents — the registered agents, what they can reach, where their work is delivered, and what happened to it.
Overview and Members answer different questions, and the console says so on the page. Overview is a record of who has used DraftMesh; Members is a record of who has been asked in. Neither is a directory of your organization — DraftMesh does not read one.
Each of the sections below has its own topic in this guide.
What is not here yet
The console is a governance surface, not a control panel for your identity provider. Single sign-on, group membership, and who is allowed to authenticate at all are configured in your WorkOS organization, not in DraftMesh. See Admin: Security posture FAQ for the full list of what does and does not live here.