Organizations
org is the customer-facing name for the resource the API and the rest of this CLI call company. vagaris org ... and vagaris company ... are the same command tree — an alias, not a second implementation — so the two names can never drift apart. Every command here accepts the shared client options (--api-base, --api-key, --context, --profile, --json; see CLI Overview). Full flag lists are on the CLI Reference.
Organization
vagaris org list
vagaris org get <org-id>
vagaris org create --name "Acme" [--description "..."] [--budget-monthly-cents 50000]
vagaris org update <org-id> [--name "..."] [--description "..."] [--status active|paused|archived|dormant] [--budget-monthly-cents 50000] [--require-board-approval-for-new-agents | --no-require-board-approval-for-new-agents] [--brand-color "#336699"] [--logo-asset-id <id>]
update sends only the fields you pass — at least one is required. status changes into any non-active state halt the organization's in-flight agent work on the server; this is a server-side effect the CLI renders, not something it computes.
Members
vagaris org member list <org-id>
vagaris org member update <org-id> <member-id> [--role owner|admin|operator|viewer] [--status pending|active|suspended]
member list returns the roster together with the caller's own effective access (canManageMembers, canInviteUsers, canApproveJoinRequests). member update requires at least one of --role/--status. Member archival and fine-grained permission-grant edits are separate, richer server routes not covered by this namespace.
Invites
vagaris org invite create <org-id> [--allowed-join-types human|agent|both] [--human-role owner|admin|operator|viewer] [--agent-message "..."] [--defaults '{"...":"..."}']
vagaris org invite list <org-id> [--state active|revoked|accepted|expired] [--limit 20] [--offset 0]
vagaris org invite revoke <invite-id>
The response from invite create carries the one-time invite token and URL — it is shown once and not retrievable again.
Policy
vagaris org policy <org-id>
Renders the organization's governance/autonomy summary (maturity, act-gates, truth-state, evolution, economics). Read-only: this command surfaces the same summary the board console reads, it does not ratify or change anything.
Delegation
There is no org delegation command. The server route that would back it (routes/delegated-access.ts) has zero HTTP endpoints today — it is consumed internally as access-check middleware (assertCompanyAccessOrDelegation), not exposed for the CLI to call. The actual delegation records live on a different service (the identity/product-plane /delegations surface), reached with a different credential than this CLI's API client uses. Until that is exposed here or proxied, delegation cannot be rendered.