Sign-up & Workspace
Organizations, projects, members, roles and API keys — the concepts that frame everything else.
AIEO.ee is multi-tenant. Understanding three nouns — organization, project, member — makes the rest of the product predictable.
Organizations
An organization (also called a workspace) owns the subscription, the credits and the members. Everything billable is measured per organization:
- one plan (Free / Pro / Growth / Agency) with its limits,
- one credit balance (GEO runs and agent actions spend credits),
- one or more members with roles.
You create an organization at sign-up; the Free plan starts immediately with no card. An organization always has exactly one owner — a database-level invariant. Ownership can be transferred (Settings → Team) but never dropped.
Projects
A project is one website (domain) inside the organization: acmecloud.io,
blog.acmecloud.io, a client site — each gets its own project with its own
tracked keywords, GEO prompts, competitors and audit history.
Plan limits apply per project (prompts, keywords) and per organization (projects count, daily GEO runs, credits). The dashboard's project switcher (top-left) sets the active project for every page.
Members & roles
| Role | Can do |
|---|---|
| owner | Everything, including billing, API keys, member management and ownership transfer. Exactly one per org. |
| admin | Everything except ownership transfer. |
| member | Use the product: view data, run GEO/SEO actions within quotas. No billing or key management. |
Invite members from Settings → Team (seat limits follow the plan; Agency is seat-billed). Invitations arrive by email and are accepted on a landing page that shows the org name before sign-in.
API keys
API keys are organization-scoped (not personal) and power the REST API and the MCP server:
readscope — every GET endpoint and every read-only MCP tool.read + write— mutating calls (POST/PATCH/DELETE) andgenerate_content_brief.
Create and revoke keys in Settings → MCP. Keys start with aieo_ and are
shown once at creation. Organization management (billing, members, keys
themselves) is deliberately not reachable with API keys — session login
only.
Data refresh schedule
The background worker keeps data fresh on a schedule (defaults run in UTC;
self-hosted instances can change them via the WORKER_*_CRON variables):
| Job | Default schedule (UTC) |
|---|---|
| GEO prompt runs (daily prompts) | daily, 07:00 |
| GEO prompt runs (weekly prompts) | weekly, Monday 07:30 |
| SEO rank checks | daily, 07:30 |
| Google Search Console sync | daily, 05:20 |
| Technical site audit | weekly, Monday 06:00 |
| Growth Agent weekly analysis | weekly, Monday 08:00 |
Every scheduled job can also be triggered manually from its dashboard page (manual runs are immediate and quota-checked the same way).