Organization Policies
Navigation
From the Organizations list, select your organization. In the sidebar, under Settings, click Policies.
Overview
Organization policies are scoped to your organization. Any policy set at the platform level takes precedence and cannot be changed for your organization; policies left unset at the platform level can be configured here.
Each policy has three states controlled by a toggle:
- Enabled — The policy is actively enforced for your organization.
- Disabled — The policy is explicitly turned off for your organization.
- Not Set — The policy inherits the platform default behavior.
Policies
No Root Access
Disable root access to cloud compute resources for all users, including resource owners, in your organization. Defaults to "Enable root access" if no policy is set.
Nitro Instance Types Only
Restrict compute resources to AWS Nitro instance types only, in your organization. Defaults to "Allow all AWS instance types" if no policy is set.
No Public IP Addresses
Prevent users in your organization from provisioning standalone public IP addresses. Defaults to "Allow public IP addresses" if no policy is set.
When enabled, requests to provision a standalone public IP address are rejected.
Archive Cost Data
Automatically summarize and then archive cost data after a specified number of months to optimize database performance. This will not delete any data, it will only summarize older data. This policy applies to the legacy cost data only; costs attributed to allocations under the flexible allocation system are not archived.
Flexible Allocation System
Choose how your organization budgets cloud spend:
- Legacy allocation system (also the behavior when No policy (legacy) is selected) — each group has an allocation total, and resources bill the Billing Group picked on them.
- Flexible allocation system — budgets are allocations, and each resource belongs to a resource group that bills one allocation.
The change takes effect immediately. Read Flexible Allocation System before switching.
Allocation Start Date
The date each year when allocation usage resets, chosen as a month and day. Allocation Used and Estimated amounts, and the thresholds that act on them, only count spend since the most recent occurrence of this date (at 00:00 UTC). For example, with October 1 set, on September 24, 2026 allocations count spend from October 1, 2025. February 29 is treated as February 28 in non-leap years.
When no policy is set, allocations count spend over all time. This policy does not limit the date ranges you can pick on the cost dashboard or in Reports.
Default Billing Username
The username shown on dashboards and reports for cost records that have no user, such as shared account charges, support, taxes, and untagged resources. It must be at least 3 characters. Because it's applied when reports are read, changing it relabels past records too.
These three settings are also shown, read-only, under Cloud > Accounts > Billing Management and on each cloud account's billing page.
Enforce Security Key MFA
Feature Preview
This policy is feature-flagged and may not be visible in your organization.
Require all users in your organization to set up and use a hardware security key (such as a YubiKey) for multi-factor authentication when logging in with a password. Users without a registered security key will be prompted to register one before accessing the platform.
Users signing in through an OpenID Connect provider with Skip Platform MFA Verification enabled are not affected by this policy; their identity provider is trusted to perform multi-factor authentication.