Everything in boring.tools — projects, uploads, findings, decisions and upload keys — belongs to an organization. Members of an organization see and work on the same data; nothing is shared between organizations.
Creating and switching organizations
Your first organization is created during onboarding. You can belong to several organizations, for example one per company or client. Create more, or switch between them, from the menu at the top of the sidebar.
Inviting members
Invite colleagues during onboarding or later under Settings → Members. They receive an email with a link; after signing in with the invited address they join the organization. Pending invitations are listed in Settings and can be withdrawn.
Roles
| Role | Can |
|---|---|
| Owner | Everything, including managing members and roles |
| Admin | Manage members, upload keys and AI triage settings, delete projects, versions and uploads, tick off CRA reporting steps, everything a member can do |
| Member | Create projects and versions, upload SBOMs, triage findings, request AI suggestions, see upload keys and reporting cases |
Deleting, AI settings and upload keys are limited to owners and admins: deleting can’t be undone, AI triage sends data to an AI provider and costs money, and keys grant access from outside. Owners and admins also get the email notifications.
Upload keys and people leaving
Upload keys belong to the organization, not to the member who created them. When someone leaves, their CI pipelines keep working. Review the keys under Settings → SBOM upload keys and delete the ones you no longer need.