Skip to main content

Organizations & projects

CertAutoPilot is organized as one organization (the tenant) containing many projects. Projects are the isolation boundary for day-to-day certificate work; org-wide resources are shared across all of them. Confusingly for newcomers, Settings → Organizations is not the tenant — it manages OV/EV organization profiles used in certificate subjects (see below).

Tenancy model

  • Users hold an org role plus optional per-project role overrides — see Auth & RBAC.
  • Most pages in the UI are scoped by the project selector in the top bar; switching projects switches every project-scoped list.

Org-wide vs project-scoped resources

Org-wide (/api/v1/...)Project-scoped (/api/v1/projects/:projectId/...)
Users, LDAP, OTP policyCertificates (issue, renew, revoke, download)
LicenseACME accounts, MSCA connections
General settings, syslogDNS credentials, zones
Organization profiles (OV/EV)Module configs & credentials, targets, target groups
CA providersDistributions, PathSets/ActionSets, project variables
Notification templatesNotification channels & rules
Org-level audit logsDomain tracking, discovery sources & inventory
Approval requests (approve/reject)Dashboard, bulk actions, certificate policy, project audit logs
Jobs (list, logs, retry, cancel)

Org-level actions check only the org role; project-scoped actions check the effective project role (most-permissive of org and project role).

Projects

Managed at Settings → Projects. Creating and deleting a project requires the org owner; editing a project's name or description requires project admin.

  • Create — name, slug (lowercase letters, numbers, hyphens; immutable after creation), optional description.
  • Edit — name and description only; the slug is fixed.
  • Delete — refused with 409 Conflict while the project still contains resources. The error lists what's still referenced (with names), so you can empty the project resource by resource; once empty, the project document is hard-deleted. Deletion requires the org owner role.

The delete is blocked by every project-scoped resource: certificates, zones, ACME accounts, Microsoft CA connections, DNS credentials, module configs, targets, target groups, module credentials, path sets, action sets, project variables, tracked domains, notification channels, notification rules, discovery sources, secret stores, discovered certificates, and the certificate policy.

note

There is no cascade delete — a project can never take certificates or credentials down with it by accident. Emptying a project is a deliberate, resource-by-resource operation.

The single exception is project-scoped role grants: they are access-control records rather than content, so they are removed with the project (org-level roles are untouched). Records that belong to a resource you already deleted — a certificate's keys and artifacts, a discovery source's endpoints — went with their parent, and the audit trail, certificate events and notification history are retained on purpose under their own retention windows.

Organization profiles (OV/EV)

Settings → Organizations manages reusable subject profiles for OV/EV certificates. DV (domain-validated) certificates don't need one — the list's empty state says exactly that. Fields are included in the CSR Subject; the CA may verify and modify them during validation.

FieldSubject attributeRequired
Organization NameO — legal name, must match official registration for OV/EVyes
CountryC — ISO 3166-1 two-letter codeyes
State / ProvinceSTyes
City / LocalityLyes
Street Addressstreet address — some CAs require it for EVno
Postal Codemay be verified during OV/EV validationno

An additional collapsed EV Certificate Fields section covers: jurisdiction country / province / locality (place of legal incorporation), registration number (government-assigned business/tax ID), incorporation date (YYYY-MM-DD, used as EV serialNumber when no registration number exists), and business category (one of the four CA/Browser Forum values: Private Organization, Government Entity, Business Entity, Non-Commercial Entity).

Deleting a profile is refused while any certificate references it (organization is referenced by N certificate(s) and cannot be deleted).

See also