大型企业通常由多个业务单元、子公司和职能部门组成。我们经常听到客户反馈,每个单元都需要独立的预算、安全、治理和功能控制。
为支持这些需求,我们推出了“组织”这一新结构,让企业能够从一个统一平台管理多个 Cursor 团队。借助该功能,管理员可以为不同团队设置独立预算,为不同用户群体启用不同模型,创建沙箱环境以测试新功能,并查看整个公司的使用分析数据——所有这些操作都在一个仪表盘内完成。
这些功能现已对所有企业客户全面开放。
结构运作方式
“组织”是公司身份、管理和成员资格的最高层级容器。这为管理员提供了一个统一视图,用于查看和管理整个 Cursor 配置。
在组织之下是“团队”,即部门或子公司的运营单元。此前,管理员是在团队层级管理 Cursor。现在,我们将这一单元移至组织之下,以便您可以运行多个团队,每个团队拥有独立的安全、支出和功能设置。对于现有客户,您原有的团队配置将保持不变。管理员可以在组织层级创建具有独立配置的新团队。
“群组”是用户的轻量级集合,可以跨团队或位于团队内部。它们为特定用户群体提供独立的模型访问权限、支出限额和智能体权限,而无需建立全新的团队。当用户属于多个团队或群组时,以权限最宽松的设置生效。
在 Cursor,我们为不同部门创建了独立的团队。工程和产品团队拥有最宽松的网络访问权限,并且能够允许智能体自动运行命令。销售、市场和财务团队则拥有更严格的安全控制,尤其是在智能体访问生产系统方面。
企业用例
在测试阶段,我们观察到客户使用这些新功能时存在几种常见模式。
沙箱测试新功能
许多有严格安全审查要求的客户都设立了预发布团队,这些团队可以提前使用 Cursor 的新功能。这些用户会在沙盒环境中测试功能,之后才会向整个公司更广泛地推送。
由于一个用户可以属于多个团队,工程师可以在其生产团队中工作的同时,保留测试团队的能力,而无需创建第二个 Cursor 账户。
我们设立了一个独立的预发布团队,在所有工程师广泛使用新 Cursor 功能之前,由该团队先行试用。我们还有另一个团队,其智能体可以在无需人工批准的情况下自动运行命令。将这些环境在一个组织下区分开来,使我们既能快速行动并采用新能力,又不会失去控制权。
Wendy Tang
NVIDIA 人工智能解决方案工程部高级软件工程师
细分模型访问权限、预算和智能体权限
一些客户正在按职能细分模型访问权限和预算。工程、产品和设计职能的用户可以访问所有前沿模型,包括更昂贵的快速模式选项,并享有更高的月度预算。
市场营销或财务等非产品职能的用户则受到限制,模型访问权限有限,预算更低,并且对智能体能否在未经人工批准的情况下运行命令有更严格的限制。
查看每个团队的详细使用分析
组织仪表盘将每个团队的支出和 token 使用情况汇总在一个视图中。可按团队、用户、服务账户或云端智能体进行筛选,以查看使用来源。团队管理员可以查看自己团队的限定视图,这有助于按业务部门或成本中心进行成本分摊。
大规模管理身份和成员资格
通过这种结构,客户只需在组织层面设置一次身份提供商和 SCIM 目录源。然后,他们可以重复使用这些工具中的同一用户群组,在 Cursor 中创建团队和群组,确保成员资格始终保持同步。
管理员可以通过仪表盘、API 或 CSV 文件在团队之间移动用户。当新用户加入团队时,设置和权限会自动应用。
下一步计划
我们正在持续增加更完善的策略控制、更简便的入职流程、基于 SCIM 的分配机制,以及更简单的用户子集管理方式,无需将每个工作流都强制归入独立的团队。
如需了解组织、团队和群组在文档中的具体运作方式,请查阅更多详情。如果您想了解更多或有任何疑问,欢迎联系我们的团队。
Large enterprises are often made up of many business units, subsidiaries, and functions. We frequently hear from customers that each of these units needs its own budget, security, governance, and feature controls.
To support these requirements, we’re introducing organizations, a new structure that allows enterprises to manage multiple Cursor teams from one place. With it, admins can set separate budgets for different teams, enable different models for different cohorts of users, create sandbox environments to test new features, and view usage analytics across the whole company, all from one dashboard.
These capabilities are now generally available to all Enterprise customers.
How the structure works
An organization is the top-level container for your company’s identity, administration, and membership. This gives admins one place to view and manage their entire Cursor configuration.
Under organizations are teams, the operating unit for a department or subsidiary. Admins previously managed Cursor at this level. We’ve now taken this unit and moved it under the organization so you can run multiple teams, each with its own security, spend, and feature settings. For current customers, your existing team setup is preserved. Admins can create new teams with separate configurations at the organization level.
Groups are a lightweight collection of users that can sit across or within teams. They give cohorts of users separate model access, spend limits, and agent permissions without standing up a whole new team. When a user belongs to multiple teams or groups, the most permissive setting wins.
At Cursor, we've created separate teams for different departments. Engineering and product teams have the most permissive network access and the ability to let agents run commands automatically. Sales, marketing, and finance have tighter security controls, especially when it comes to agents accessing production systems.
Enterprise use cases
There are a few common patterns we've seen from customers using these new capabilities in beta.
Sandboxing to test new features
Many customers with strict security review requirements have set up a staging team that gets early access to new Cursor features. These users test features in a sandboxed environment before they are rolled out more broadly to the full company.
Because a user can belong to more than one team, engineers can work in their production team while retaining testing team capabilities without having to create a second Cursor account.
We have set up a separate staging team that tries out new Cursor features before they are released broadly to all our engineers. We have another team where agents can run commands on auto-run without manual approval. Keeping those environments distinct under one organization lets us move quickly and adopt new capabilities without sacrificing control.
Wendy Tang
Staff Software Engineer, AI Solutions Engineering, NVIDIA
Segmenting model access, budgets, and agent permissions
Some customers are segmenting model access and budgets across functions. Users in engineering, product, and design functions get access to every frontier model, including more expensive offerings with fast mode, and higher monthly budgets.
Users in non-product functions like marketing or finance have restricted model access, lower budgets, and tighter restrictions on whether agents can run commands without manual approval.
See detailed usage analytics across every team
The organization dashboard rolls up spend and token usage across every team in one view. Filter by team, user, service account, or cloud agent to see where usage comes from. Team admins keep a scoped view of their own team, which supports chargebacks by business unit or cost center.
Manage identity and membership at scale
With this structure, customers set up their identity provider and SCIM directory source once at the organization level. They can then re-use the same cohorts from these tools to create teams and groups in Cursor, ensuring that membership always stays in sync.
Admins can move users between teams through the dashboard, API, or CSV. And when a new user joins a team, settings and permissions apply automatically.
What's next
We’re continuing to add better policy controls, easier onboarding, SCIM-driven assignment, and simpler ways to manage subsets of users without forcing every workflow into separate teams.
Read more detail on how organizations, teams, and groups work in our docs. Please reach out to our team if you'd like to learn more or have questions.