Organization account

Enter an organization without making identity the role system.

This surface begins an organization-oriented journey while preserving the boundary between verified identity, organization membership, product roles, and resource authorization.

First-party Shared Auth surfaceorg.ores-shared-auth.com
PUBLIC HOSTexact match
EDGECloudflare Workerhost → service
AUTHORITYShared Authidentity ≠ authorization

Membership is a separate proof.

A valid Shared Auth session is necessary but not sufficient. The target product must resolve the selected organization, membership status, role, and resource policy independently.

Continue through Shared Auth

Authenticate first, then let the destination application present its organization chooser and enforce its own authorization rules.