Account & Organization
Your Palmata account is separate from your organization memberships. You can belong to multiple organizations or have no memberships. Reports belong to the organization. This page covers who can do what, how people join, and the settings that are yours and yours only.
Opening a report in another organization
If a report link belongs to another organization you belong to, Palmata shows that organization’s name and a Switch to [organization name] button. Click it to change your active organization and open the report at the same link. Choose Back to reports to stay in your current organization.
You only see this option when you have access to the report. Reports in organizations you haven’t joined, and private reports you can’t view, remain unavailable.
Roles
Everyone in an organization has one of four roles. The role decides what they can do.
- Owner — the organization’s top authority. Can do everything an admin can, plus manage admins. There’s one owner.
- Admin — runs the organization day to day: invites and removes people, changes roles, approves report requests, and manages billing.
- Creator — builds reports directly. The working role for anyone doing audits.
- Member — can view shared reports and request a report, but can’t build one without an admin’s sign-off.
The split that matters most in daily use is creator vs. member. Both roles can open New Report and configure the audit. A creator submits it with Build report; a member uses Request report to send the same setup to the admins — see Report requests below.
The organization page

Open the organization page from the side navigation. The available tabs depend on your role and the features enabled for your organization:
- Members — everyone in the org. Visible to all roles.
- Report Requests — pending report requests waiting on approval. Admins only.
- Billing — plan and credits. Admins only. See Billing.
- Settings — rename the organization. Admins only.
- Sub-organizations — create and manage nested organizations at any depth when organization administration is enabled.
- Access requests — review requests from people with the family’s email domain. Available to owners and admins of the top-level organization when organization administration is enabled.
Members see only the Members tab. The admin tabs appear when your role can use them.
Organizations workspace
When organization administration is enabled, owners and admins see Organizations in the sidebar. Its tree combines member management and sub-organization management. Existing Members and Sub-organizations URLs both open this workspace. Other roles retain the Members page shown above.
Click an organization name to view it, or check several organizations to manage them together. Include descendants includes their nested organizations. Search the sidebar to find an organization and its ancestor path. Checked selections survive filtering. Expand or collapse branches with the arrow beside each name. Long trees scroll within the sidebar; deep names can scroll horizontally.
Members and invitations
Members shows each person once, with their role in every organization in the selected scope. Memberships run horizontally across the row and scroll when needed. Search filters people by name or email.
Select people and click Add to organizations to invite them to other organizations. Search the destination list, check the organizations, choose a role, then click Start invitations. Selections remain checked when you search for another destination. Invite people accepts email addresses separated by commas or new lines. These invitations appear in the recipient’s account; this workspace does not send invitation emails. Membership starts after acceptance. Existing memberships and pending invitations are skipped.
Use Change roles or Remove memberships on selected people to change only the memberships shown in the current scope. Owners and your own membership are protected. Removing a membership ends that person’s access to that organization and its reports. Invitations lists pending offers; Revoke prevents an offer from being accepted.
Actions show progress while you continue browsing. Activity shows completed, skipped and failed items. Keep the tab open until actions finish; activity lasts for the current app session.
Organization settings
Select one organization, then click Create sub-org to add a child. In Settings, use Rename, Change parent, Archive or Restore. Changing the parent moves the whole subtree within the same family. You need administrative authority over both the old and new parents. Members and reports stay in their organizations; administrative authority follows the new hierarchy. A root organization cannot be moved or archived here.
Owners and admins can administer descendants without joining each one. Selecting a descendant keeps your active report organization unchanged. Parent owners and admins inherit admin access by default, including reports, settings, and credits, without joining each descendant. A child admin’s tree starts at their organization and includes its descendants.
Organization hierarchies cannot contain cycles. Archive active descendants before archiving their parent, and restore ancestors before restoring a child. Active report jobs and billing can block archival. Archival disables schedules and revokes pending invitations; restoring an org does not restart its schedules.
Settings → Member controls retains email verification, MFA reset and creator spend limits for the selected organization. These controls require direct or inherited admin access.
Sub-organizations have Settings → Inherit admin access from parent organizations enabled by default. Turning it off stops access inherited from ancestors through that branch. Explicit memberships remain. Admins within the branch can still inherit access in its descendants. Turning inheritance back on requires an admin who still has access to that organization.
Members without organization administration
The Members page lists everyone in your organization and filters by name or email. Admins use Invite to invite a co-worker by email. Depending on the family’s joining policy, access may require acceptance or follow the existing automatic joining behavior. Co-worker invitations offer the member role.
Admins change roles or remove people with each member’s dropdown. Owners can promote members to admin. Removal ends access immediately; an owner must transfer ownership before leaving or being removed.
Access requests
For organization families that require approval and have domain discovery enabled, a verified account with a matching email domain can receive a pending access request. A matching domain alone does not grant membership.
In Access requests, a top-level owner or admin selects one or more active organizations at any depth in the family and a role for each, then clicks Approve invitations. Approval creates invitations; the person chooses which to accept. Decline closes the request without granting access. The page also shows previous decisions.
Report requests
When a member asks for a report, it doesn’t run — it lands in the Report Requests tab as a pending request. An admin reviews it and either approves it, which starts the build and spends a credit, or declines it. The requester is notified when their request is approved and the report begins building.
This is how organizations let people surface what they need audited without handing every seat the ability to spend credits.
Account settings

Your account settings are separate from the organization and apply only to you. Open them from your account menu.
- Name — edit the display name others see on your invites and activity.
- Password — request a reset email to set a new password.
- Notifications — toggle the email notifications you receive (report finished, request approved, and similar). Turn off anything you don’t want.
- Organizations — when organization administration is enabled, review all your memberships and pending invitations. Accept or decline invitations, hide or show an organization in the switcher, or leave it. Hiding preserves membership and report access; hidden organizations remain listed here so you can show them again. Inherited admin access is labeled and has no Leave action; change the organization’s inheritance setting or the parent membership instead. Leaving a direct membership requires a new invitation to rejoin; inherited admin access may still apply. An owner must transfer ownership before leaving.
- Delete account — permanently remove your account. You’ll confirm with your password. This is irreversible.
Signing in
Palmata reconnects automatically if your session check is interrupted. If your session has expired, Palmata takes you to sign-in.
Palmata accounts use email and password. A few details worth knowing:
- Email verification — new accounts confirm their email with a one-time verification code before the account is active.
- Two-factor authentication — if your account has 2FA enabled, you’ll enter a code from your authenticator app after your password.
- Forgot password — request a reset link from the login screen; it emails you a link to set a new one.
After verification or sign-in, an account without memberships opens Welcome to Palmata. Pending invitations appear with Join and Decline buttons. If access is awaiting approval, the page names each requested organization and explains that an organization administrator must approve the request. Use Refresh to check for approved invitations. If your email domain matches an active organization but automatic joining is turned off, the page names the organization and explains that you need an invitation. This does not mean a request has been submitted. Other invitation-only matches also explain that an invitation is required. If there is no matching organization or invitation, support and sign-out remain available. Leaving your final organization returns to this account screen.
Some organizations restrict signups to specific email domains. When public signup is disabled, a signup request can still require staff review before an account is created.
The workspace keeps organization actions in its detail tabs: Members contains People, Invitations, and family-root Access requests. Report requests, Settings, and Billing & Credits apply to the selected organization. Select one organization for these tabs. Settings, report requests and billing accept direct or inherited admin access. Selecting an organization in the tree does not change your active organization.