Overview

Multi-user collaboration with enterprise-grade access control

Opik Cloud and Enterprise include administration features for teams and organizations, including:

  • Role-based access control: Assign granular permissions at the organization and workspace level
  • Single sign-on (SSO): Authenticate users via SAML or OIDC with your identity provider
  • Workspace isolation: Separate projects and data across teams with independent access controls
  • Service accounts: Create API keys for CI/CD pipelines and automated workflows
  • User management: Invite team members, assign roles, and manage access from a central dashboard
  • JWT authentication: Integrate Opik into existing systems with token-based auth

Available on Opik Cloud and Enterprise. Contact us for Enterprise pricing.

Get started

Key concepts

Opik uses a hierarchical structure to organize users and data:

TermDescription
OrganizationYour company or team. Contains all users, workspaces, and billing settings.
WorkspaceA container for projects. Users can belong to multiple workspaces with different roles in each.
ProjectA container for traces. Experiments and datasets live at the workspace level.
Organization RoleControls organization-wide permissions (e.g., Admin can manage billing and users).
Workspace RoleControls what a user can do within a specific workspace (e.g., Editor can create projects).

Here’s how these concepts relate:

We recommend creating one workspace per team. This keeps projects organized and allows you to assign different roles to team members based on their responsibilities.