All
Filter by:
How do I deposit cash into my account?
I need help with account verification
Why can't I access my account?
Are there any crypto withdrawal fees?
I need help signing into my account
Organizations lets institutional clients run a team of traders, operators, and approvers across multiple segregated accounts, with approval workflows guarding fund movements, every administrative change, and the governance rules themselves.
Creating an Organization will allow you to:
An Organization is the top-level container that brings together the accounts you operate, the people and credentials that operate them, and the governance rules that sit over both.
Organization Owner - The account holder who created the Organization. The Owner starts with full access to every workflow and account and is responsible for setting up the team and its governance. There is no co-owner role.
Member - A person invited to the Organization. Members sign in with their own Kraken credentials, must comply with the Organization Sign-in 2FA policy, and hold exactly one Workflow Profile plus any number of Account Roles.
Accounts - The segregated operating units inside an Organization, each with its own balances, open orders, and history. An Organization starts with a main account and can hold several; access to one account never carries over to another. See Accounts.
API key - A credential for programmatic access, used by trading systems and automation. API keys have their own permission model, separate from Members. See API keys.
Everything a Member does in an Organization falls into one of two categories. Understanding this split makes the rest of the model straightforward.
Direct operations take effect immediately. Viewing balances, trading, and allocating funds to Earn products are direct operations: if a Member holds the account permission on that account, the action happens right away. Direct operations never create approval requests.
Governed operations run as approval requests. Withdrawals, transfers between accounts, and every administrative change (managing team access, API keys, accounts, addresses, and policies) are governed operations. Starting one creates a request, and the workflow’s policy decides whether that request completes immediately or waits for approval from other Members.
Direct operations | Governed operations | |
|---|---|---|
Examples | Read balances, Trade, Earn allocate and deallocate | Withdraw, Transfer, invite a Member, create an API key, change a policy |
Controlled by | Account permissions, granted per account through Account Roles | Workflow Profile levels plus the workflow's approval policy |
Completion | Immediate | Immediate or after approval, depending on the policy configuration |
Governed operations are organized into workflows. Each workflow has its own approval policy and its own View / Initiate / Approve / Execute levels in every Member’s Workflow Profile.
Workflow | What it controls |
|---|---|
Withdrawal Request | Withdrawals to whitelisted external addresses |
Transfer Request | Fund movements between your Organization’s accounts |
Manage Team & Access | Member invitations, activation, Account Roles, and Workflow Profiles |
Manage API Keys | Creating, editing, and revoking API keys |
Manage Accounts | Account lifecycle, adding, editing, disabling, and deleting accounts |
Manage Addresses | The whitelist of withdrawal destinations |
Manage Policies | The approval rules that govern every other workflow |
Organization - The top-level container that groups Members, accounts, and governance under a single structure.
Account - A segregated operating unit with its own balances, open orders, and history. Access to one account never carries over to another.
Main account - The account that existed when the Organization was created. It supports spot and margin trading for Members; additional accounts currently support spot trading. See Availability and limitations.
Account permission - A grant that authorizes a specific operation on a specific account: Read, Trade, Earn Allocate, Earn Deallocate, Withdraw, or Transfer.
Account Role - A reusable bundle of account permissions applied to a set of accounts. A Member can hold several Account Roles; their permissions combine.
Workflow - A group of related governed operations that share one approval policy: Withdrawal Request, Transfer Request, Manage Team & Access, Manage API Keys, Manage Accounts, Manage Addresses, and Manage Policies.
Workflow Profile - The single profile each Member holds, defining their level (View, Initiate, Approve, Execute) on each workflow. Workflow Profile levels apply across the whole Organization.
Policy - The approval configuration of one workflow: how many approvals a request needs, and whether every request must go through approval. Policies are set per workflow, once for the whole Organization.
Request - The unit of work created when a Member or API key starts a governed operation. A request either completes immediately (when the policy allows) or waits in the approval queue.
Security event - A record of an action that happened in your Organization: who did it, from where, on which account, and with what result. See Security events.
Separation of duties - The rule that a Member cannot approve their own request. Enforced by the system and not overridable.
Some capabilities are still rolling out. See Availability and limitations for what is available today.
Start with Create an Organization, then Roles, profiles, and permissions, Policies, approvals, and governance, and Rolling out governance. Use the other articles when you need to manage a specific part of your Organization.