Organizations
Organizations
An organization is a shared PacketSafari workspace. Its members can work from the same organization-visible captures, cases, tags, profiles, saved filters, AI investigations, and reports without making that material public.
Open Settings → Organization to see your role, workspace policies, pooled storage, and AI usage. Organization owners and admins can also see the member roster and pending invitations and manage retention, security policy, an optional organization AI provider, ingestion service accounts, and the audit log. Regular members do not receive member email addresses, pending invitations, or AI-provider configuration from the organization API. PacketSafari platform administrators can manage any organization from Admin → Organizations.
Inviting members
Create an invitation for the exact email address stored on the person's PacketSafari account. The link is single-use, expires, and will fail if opened under a signed-in account with a different stored email. Pending invitations count against the seat limit. An allowed-domain policy can restrict which addresses may be invited.
Roles are:
- Owner — full governance, including granting or transferring the owner role.
- Admin — day-to-day governance for security, retention, AI, invitations, and ordinary memberships. Admins cannot grant, modify, or remove an owner.
- Member — access to shared work and usage information without governance changes.
Owners and platform administrators are the only roles that can invite a new owner or change an existing owner membership. Transfer ownership before deactivating the organization's only active owner.
Capture visibility
New uploads use the organization's default: organization or private. Organization visibility means every active member can read the capture while the organization is active and its entitlement has not expired; it does not make the capture public. Existing captures are never exposed merely because their owner joins an organization. An owner/admin must explicitly adopt an owned historical capture.
Capture-derived cases, tags, profiles, saved filters, chats, and reports inherit the stable organization boundary. Removing a member removes organization access without changing the resource's stored organization owner.
Choose the upload workspace
If your account belongs to one active organization, PacketSafari selects it automatically during upload. If it belongs to more than one, the upload dialog requires you to choose Organization workspace before the file can be submitted. The selected workspace becomes the capture's stable owner and supplies its visibility, pooled quota, retention, AI-provider, and analysis capacity policy.
Selecting another workspace for a later upload does not move earlier captures. An expired or otherwise unavailable organization is not offered for new uploads and no longer authorizes access to its organization-visible resources.
Retention and legal holds
Retention can archive older captures, schedule deletion at a chosen age, and wait through a deletion grace period before purge. Each new capture records the policy active when it was uploaded, so a later policy edit does not silently shorten its existing lifetime.
Automatic retention is not enabled merely by purchasing Enterprise. An organization owner/admin must enable it explicitly, or the Enterprise contract must contain customer-approved retention terms. Contract renewals without such terms preserve the organization's existing policy.
A legal hold overrides archive and deletion. Setting a hold during the grace period cancels the pending purge until an owner/admin clears the hold. Retention warnings, holds, and purge events appear in the organization audit log.
Pooled quotas
Storage, processed capture data, weighted Agent units, and Copilot messages are shared organization capacity. The usage cards show the counters used for enforcement. A new upload or AI run is rejected when it would exceed the pooled limit. Archived data still counts by its original logical capture size until it is purged. An accepted full-processing ingest meters retained capture bytes once toward the monthly processed-data allowance; store-only ingestion meters zero. Each accepted explicit post-index, infrastructure-scan, or deferred- materialization operation meters one retained capture size. Failed queue admission does not count. Organization reprocessing requires an idempotency key; a committed replay does not count again and a pending replay is rejected.
| Included capacity | Shared Enterprise | Dedicated Enterprise |
|---|---|---|
| Named users | 5 | 5 |
| Capture upload | 5 GiB | 5 GiB |
| Active storage | 100 GiB | 250 GiB |
| Processed capture data/month | 250 GiB | 1 TiB |
| Weighted Agent units/month | 500 | 2,000 |
| Copilot messages/month | 2,500 | 10,000 |
| Automatic capture retention | Opt-in; suggested 30 days | Opt-in; suggested 90 days |
| Analysis capacity | Shared priority Agent and indexing queues | One reserved Agent slot and one reserved indexing slot |
A focused standard-model run costs one unit. Fast + verification and a focused strongest-model run cost two; deep investigation on the strongest model costs four.
The progressive Fast + verification upload workflow uses a fixed validated
progressive runtime profile, meters 2 Agent units once, and includes its
preliminary and independent verification passes.
Your organization page shows the pooled usage, active capacity class, and
Dedicated provisioning status.
Purchased seat, storage, processed-data, Agent, Copilot, and Dedicated reserved-capacity add-ons are applied from the external contract order by a PacketSafari platform administrator. Retried fulfillment does not add the same order twice.
Organization AI
An owner/admin may configure an OpenAI, OpenAI-compatible, Ollama, or LM Studio endpoint for the organization. The organization provider is used by Agent, Copilot, display-filter assistance, and upload-triggered investigations, including work that starts later in a background worker. The API key is encrypted and is never shown again.
To configure it:
- Open Settings → Organization → Organization AI.
- Enable the provider, choose its type, and enter its API base URL. Most
OpenAI-compatible servers use a URL ending in
/v1. - Enter the exact default model ID and strongest model ID. You can enter these manually even when the server does not expose model discovery.
- For managed SaaS, select Request URL approval. This emails PacketSafari operations for review; it does not save the provider, change the deployment allowlist, or grant network access. Only a PacketSafari platform operator can approve the host. On-prem administrators instead use the host approval command shown by their own installation.
- After the URL is approved, enter the API key if required and select Save provider.
- Select Test connection, then Refresh models. The discovered runtime catalog becomes the model selector for organization members.
The default model handles normal requests. The strongest model handles the Max tier. If the provider has only one model, use the same ID for both. A custom organization catalog is shown as concrete model choices, including on SaaS; SaaS users without a custom organization provider continue to see the public Fast, Deep, and Max choices.
Organization credentials take precedence for members unless the security policy permits personal credentials and a member explicitly selects one. The worker retrieves the encrypted organization secret at execution time; it does not replace the organization endpoint with the deployment-wide provider.
Pooled Agent and Copilot quotas still apply when the organization supplies the model endpoint. A focused standard-model run costs one unit; Fast + verification and focused strongest-model runs cost two; deep strongest-model runs cost four. The organization AI spend limit is also enforced, but cost reporting for an arbitrary compatible model depends on that model having pricing metadata; unit limits remain the reliable hard budget for unknown custom models.
For Shared or Dedicated managed SaaS, the custom endpoint must be a PacketSafari-operator-approved public HTTPS URL. Private RFC1918/LAN-only endpoints are rejected; entering an internal URL cannot create a network route. Use On-Prem Enterprise, or a separately designed operator-managed private connectivity option, when the provider must stay on a customer network. On-prem deployments may also require explicit egress-host approval and private CA installation. See Local Models and External AI Approval.
On-prem administrators can also manage the deployment-wide provider under application administration. Organization configuration is useful when separate business units require separate credentials or compatible endpoints.
Service accounts and ingestion keys
Open Manage capture probes from the organization page to create service accounts and scoped ingestion keys. Keys are displayed once, can expire or be revoked, and can be restricted by scope. Captures imported by an organization probe automatically enter that organization's visibility and retention policy.
Security and audit
Owners/admins can require MFA, restrict invitation email domains, set inactivity and concurrent-session limits, disable capture downloads, disable public sharing, and control personal AI credentials. If MFA is required, enable it in Account → Security. After SAML, OIDC, or social sign-in, PacketSafari may also ask for an authenticator or recovery code to verify that browser session.
The audit view records organization administration, invitation, retention, legal-hold, AI-provider, and ingestion-key activity. Owners/admins can export it as CSV for customer review or compliance evidence.
