About Organizations

Last updated: 17 Eost 2026
Note:

If your Organization was set up under the Beta access model, where permissions were granted to each Member individually, see Moving from Beta. It covers what changes, and the API integration work to complete beforehand.

Organizations at a glance

Organizations lets institutional clients run a team of traders, operators, and approvers across multiple segregated accounts, with approval workflows guarding fund movements, every administrative change, and the governance rules themselves.

Creating an Organization will allow you to:

  • Operate multiple accounts with segregated balances, orders, and history
  • Invite team members and assign access with reusable roles and profiles
  • Require multi-party approval for withdrawals, transfers, and administrative changes
  • Rebalance your accounts with transfers that never leave the Organization, reviewed and approved like any other fund movement
  • Create API keys for automated trading, including FIX connectivity on spot markets, and reporting, each key scoped to the accounts it operates
  • Review a security event trail of everything that happens in your Organization

An Organization is the top-level container that brings together the accounts you operate, the people and credentials that operate them, and the governance rules that sit over both.

Organization Owner - The account holder who created the Organization. The Owner starts with full access to every workflow and account and is responsible for setting up the team and its governance. There is no co-owner role.

Member - A person invited to the Organization. Members sign in with their own Kraken credentials, must comply with the Organization Sign-in 2FA policy, and hold exactly one Workflow Profile plus any number of Account Roles.

Accounts - The segregated operating units inside an Organization, each with its own balances, open orders, and history. An Organization starts with a main account and can hold several; access to one account never carries over to another. See Accounts.

API key - A credential for programmatic access, used by trading systems and automation. API keys have their own permission model, separate from Members. See API keys.

Everything a Member does in an Organization falls into one of two categories. Understanding this split makes the rest of the model straightforward.

Direct operations take effect immediately. Viewing balances, trading, and allocating funds to Earn products are direct operations: if a Member holds the account permission on that account, the action happens right away. Direct operations never create approval requests.

Governed operations run as approval requests. Withdrawals, transfers between accounts, and every administrative change (managing team access, API keys, accounts, addresses, and policies) are governed operations. Starting one creates a request, and the workflow’s policy decides whether that request completes immediately or waits for approval from other Members.

Direct operations

Governed operations

Examples

Read balances, Trade, Earn allocate and deallocate

Withdraw, Transfer, invite a Member, create an API key, change a policy

Controlled by

Account permissions, granted per account through Account Roles

Workflow Profile levels plus the workflow's approval policy

Completion

Immediate

Immediate or after approval, depending on the policy configuration

Governed operations are organized into workflows. Each workflow has its own approval policy and its own View / Initiate / Approve / Execute levels in every Member’s Workflow Profile.

Workflow

What it controls

Withdrawal Request

Withdrawals to whitelisted external addresses

Transfer Request

Fund movements between your Organization’s accounts

Manage Team & Access

Member invitations, activation, Account Roles, and Workflow Profiles

Manage API Keys

Creating, editing, and revoking API keys

Manage Accounts

Account lifecycle, adding, editing, disabling, and deleting accounts

Manage Addresses

The whitelist of withdrawal destinations

Manage Policies

The approval rules that govern every other workflow

Organization - The top-level container that groups Members, accounts, and governance under a single structure.

Account - A segregated operating unit with its own balances, open orders, and history. Access to one account never carries over to another.

Main account - The account that existed when the Organization was created. It supports spot and margin trading for Members; additional accounts currently support spot trading. See Availability and limitations.

Account permission - A grant that authorizes a specific operation on a specific account: Read, Trade, Earn Allocate, Earn Deallocate, Withdraw, or Transfer.

Account Role - A reusable bundle of account permissions applied to a set of accounts. A Member can hold several Account Roles; their permissions combine.

Workflow - A group of related governed operations that share one approval policy: Withdrawal Request, Transfer Request, Manage Team & Access, Manage API Keys, Manage Accounts, Manage Addresses, and Manage Policies.

Workflow Profile - The single profile each Member holds, defining their level (View, Initiate, Approve, Execute) on each workflow. Workflow Profile levels apply across the whole Organization.

Policy - The approval configuration of one workflow: how many approvals a request needs, and whether every request must go through approval. Policies are set per workflow, once for the whole Organization.

Request - The unit of work created when a Member or API key starts a governed operation. A request either completes immediately (when the policy allows) or waits in the approval queue.

Security event - A record of an action that happened in your Organization: who did it, from where, on which account, and with what result. See Security events.

Separation of duties - The rule that a Member cannot approve their own request. Enforced by the system and not overridable.

  • Members cannot approve their own requests, on any workflow, under any configuration.
  • Access is additive. Members start with no access and gain only what their Workflow Profile and Account Roles grant.
  • Whether a governed operation completes immediately or waits for approval depends on the Member’s Workflow Profile and the workflow’s policy, never on the operation alone.
  • Changing or unlocking a locked policy always waits for independent approval from Members whose Workflow Profile grants approval on Manage Policies. No one, the Owner included, can change a locked policy single-handedly.
  • Organization Sign-in 2FA is required for every Member. The policy is set at creation and applies to all current and future Members.
  • Idle sessions expire and require re-authentication.
  • Every sign-in, permission change, fund movement, and policy change is recorded as a security event.
  • You need a Business verified Kraken account on Kraken Pro to create an Organization. Standard and Starter accounts are not eligible.
  • Only the account holder who completed business verification can create an Organization. After creation, this person becomes the Organization Owner.
  • The Owner’s email address can be changed later through the regular Email Change flow. Expect ID verification and possibly a manual review as part of that process.
  • Reverting an Organization requires support, can take time, and only happens after the required conditions are satisfied.
Note:

Some capabilities are still rolling out. See Availability and limitations for what is available today.

Start with Create an Organization, then Roles, profiles, and permissions, Policies, approvals, and governance, and Rolling out governance. Use the other articles when you need to manage a specific part of your Organization.

Need more help?