DevelopmentNew Release12 min readPublished June 6, 2026

Per-team budgets · model-tier segmentation · SCIM Groups — all from one admin console

Cursor Organizations: Govern Enterprise AI Coding at Scale

Cursor shipped Organizations for Cursor Enterprise on June 3, 2026 — a top-level container that gives admins one dashboard for multiple teams, with separate budgets, model access, and governance per unit. It is the clearest sign yet that the AI coding race has moved from raw capability to enterprise control.

DA
Digital Applied Team
Senior strategists · Published Jun 6, 2026
PublishedJun 6, 2026
Read time12 min
SourcesCursor blog, docs + 6 others
Organizations GA
Jun 3'26
all Enterprise customers
Fortune 500 reach
~⅔
64% vendor / ~67% Fortune
Cursor ARR
$2B+
Feb 2026 milestone
Enterprise revenue
~60%
of total, up from ~25%
+35 pts

Cursor Organizations is the AI coding tool's new enterprise governance layer, announced on June 3, 2026, and it reframes the buying conversation around control rather than capability. Per Cursor's announcement, Organizations sits above the existing Teams structure as a company-level container: one dashboard, a rollup of spend and token usage across every team, and separate security, budget, model-access, and feature settings for each operating unit.

The launch matters because of who is buying. Cursor reports that it now serves a large share of the Fortune 500, and independent reporting puts enterprise at roughly 60% of its revenue — up from about a quarter eighteen months earlier. When most of your money comes from large organizations, the product that retains them is not a smarter autocomplete; it is the admin console that lets a CISO, a finance lead, and an engineering director all sign off on the same rollout.

This guide covers exactly what Organizations ships, how its three-tier hierarchy and spend controls work, where it lands against GitHub Copilot Enterprise governance, and one design decision — Cursor's documented "most permissive setting wins" rule — that security teams should scrutinize before they standardize. Every feature claim below is attributed to Cursor's own blog, changelog, and documentation, with third-party figures called out as such.

Key takeaways
  1. 01
    Organizations is a company-level governance container.Announced June 3, 2026 and generally available to Enterprise customers, it gives admins one dashboard to manage multiple Cursor teams, view a rollup of spend and token usage, and configure security, governance, budget, and feature settings per team.
  2. 02
    Three tiers: Organization, Teams, Groups.The Organization is the company identity and admin container; Teams are operating units (departments, regions, subsidiaries) with independent settings; Groups are lightweight collections that grant separate model access, spend limits, and agent permissions without spinning up a whole new team.
  3. 03
    Function-based model segmentation is the headline use case.Cursor names this directly: engineering, product, and design can be granted frontier models and higher budgets, while marketing, finance, and non-product roles get restricted model access, lower budgets, and tighter controls on auto-running agent commands.
  4. 04
    Cursor includes SSO earlier in its tier ladder than Copilot.Per the vendors' pricing pages, Cursor includes SAML/OIDC SSO on its Teams plan, while GitHub Copilot reserves SAML SSO for the Enterprise plan and offers none on Business — a concrete access-tier difference for mid-market buyers.
  5. 05
    Watch the 'most permissive setting wins' rule.Cursor's blog states that when a user belongs to multiple teams or groups, the higher-access setting applies. For the settings Cursor documents, that favors velocity over least-privilege — the opposite of how enterprise policies usually cascade. Name the trade-off before you trust the defaults.

01What ShippedOne dashboard for many teams.

According to Cursor's announcement, Organizations is "the top-level container" that lets Enterprise admins manage multiple teams from one place. The dashboard surfaces a rollup of spend and token usage across the whole company and exposes per-team configuration for security, governance, budgets, and features. Cursor describes it as generally available to all Enterprise customers, paired with Teams pricing changes announced the same week.

The framing in Cursor's changelog is blunt about the job to be done: enterprises can now run distinct security, governance, budget, and feature controls for each team while keeping a single company-level view. That is a structural shift. Until this release, a large company running Cursor across several departments effectively managed a set of loosely related team accounts; Organizations gives them a parent account with real administrative gravity.

Container
The Organization
Company-level identity + admin

One dashboard, one rollup of spend and token usage across every team. Security, governance, and feature settings configured centrally. Generally available to Enterprise customers as of June 3, 2026.

cursor.com/blog/organizations
Operating units
Teams
Departments · regions · subsidiaries

Each team carries its own settings — distinct security, governance, budget, and feature controls — while remaining visible in the org-wide rollup. The unit you actually budget and govern against.

Independent per-team config
Lightweight
Groups
Collections within or across teams

Grant separate model access, spend limits, and agent permissions to a slice of users without provisioning a full new team. The mechanism behind function-based segmentation.

SCIM-syncable
Release snapshot
Cursor announced Organizations for Cursor Enterprise on June 3, 2026, generally available to Enterprise customers. It pairs a company-level admin dashboard — spend and token rollups, centralized security and governance — with per-team controls, and arrived the same week Cursor restructured its Teams pricing. Treat every capability here as documented by Cursor; verify the exact feature set on Cursor's announcement before a production rollout.

One detail in the announcement is easy to miss and matters operationally: the identity provider is configured once at the organization level and reused across every team and group, which removes the per-team IdP setup duplication that plagued multi-team deployments before. Admins can move users between teams via the dashboard, an API, or CSV bulk import — table stakes for any company past a few hundred seats.

02The HierarchyOrganization, Teams, and Groups.

The structure is three layers deep, and each layer answers a different governance question. The Organization is the company-level identity and admin container — the single pane of glass. Teams are the operating units: departments, regions, or subsidiaries, each with its own independent settings. Groups are the lightweight layer — collections of users that can span teams or sit inside one, carrying their own model access, spend limits, and agent permissions without forcing you to stand up an entire new team.

Groups are the quiet workhorse of the design. Before this layer existed, granting a subset of users different model access or a tighter agent policy meant either a new team (heavy) or no granularity at all (risky). Groups make per-function policy a lightweight assignment rather than an org-chart change — which is precisely what makes the segmentation use case in the next section practical at scale.

"Keeping those environments distinct under one organization lets us move quickly and adopt new capabilities without sacrificing control."— Wendy Tang, Staff Software Engineer, NVIDIA

Cursor cites a sandbox-staging pattern as a named use case: a company can stand up a staging team to pilot new features while the same users participate in both the staging and production teams without duplicate accounts. For engineering organizations that already run a ring-based rollout model for their own software, the appeal is obvious — the tool they build with now mirrors how they ship.

03Model & Budget SegmentationFrontier models for engineering, guardrails for the rest.

This is the use case Cursor leads with, and it is the most commercially honest one. Per the announcement, engineering, product, and design users can be granted access to all frontier models — including the expensive fast-mode offerings — plus higher monthly budgets. Marketing, finance, and other non-product roles get restricted model access, lower budgets, and tighter controls on whether agents can run commands automatically. The whole thing is configured from one admin console.

The economic logic is straightforward. Frontier fast-mode inference is the most expensive thing a Cursor seat can consume, and the people who justify it are the ones shipping production code. Letting a finance analyst's occasional agent run pull from the same frontier pool is pure cost leakage. Segmenting model access by function is the single highest-leverage budget control an enterprise can set — and until Groups existed, there was no clean way to express it.

Engineering / product / design
Frontier + fast-mode access
Allmodels

Granted access to all frontier models including premium fast-mode offerings, with higher monthly budgets. The cohort that justifies the most expensive inference because it ships production code.

Higher budgets
Marketing / finance / non-product
Restricted by design
Lower

Restricted model access, lower budgets, and tighter controls on whether agents can run commands automatically. Stops cost leakage from occasional users drawing on the premium pool.

Auto-run gated
Assignment unit
Policy without org change
1group

Each policy attaches to a Group, so re-scoping a function's model and budget access is a membership change — not a new team and not an org-chart rewrite.

SCIM-driven

If you run a mixed organization where different roles genuinely need different tools, this maps cleanly onto how we already think about it in our AI digital transformation engagements: the model is a per-function decision, not a per-company one. A governance layer that encodes that distinction is doing real work, not shipping a checkbox. For the adjacent question of which roles should get which agentic tools at all, our breakdown of OpenAI Codex for every role covers the function-by-function logic in depth.

04Spend ControlsA three-tier spend hierarchy that honors the most specific limit.

Budgets are where governance gets concrete. Per Cursor's documentation, enterprise spend limits cascade across three levels — group, team, and organization — and the system honors the most specific limit that applies to a given user. On pooled enterprise accounts, those limits apply to total usage, not just on-demand spend, and admins can set dynamic limits that auto-adjust proportionally as headcount grows or shrinks.

The proprietary table below maps Cursor's three-tier spend model. The mental model worth internalizing is the interaction rule: where GitHub Copilot's enterprise budgets apply a "lowest remaining headroom wins" principle across its budget types, Cursor's spend limits resolve to the most specific level. Those are different philosophies — one optimizes for the tightest cap, the other for the most locally-relevant cap — and a finance team should know which one it is buying.

Cursor Organizations three-tier spend hierarchy: who sets each limit, what it caps, how limits interact, and the plan required.
LevelWho sets itWhat it capsInteraction rule
GroupOrg / team adminTotal usage for a function or role sliceMost specific — applied first where present
TeamOrg / team adminTotal usage for a department, region, or subsidiaryApplies when no group limit is set
OrganizationOrg adminTotal company-wide pooled usageBackstop cap; least specific
Dynamic scalingOrg admin (opt-in)Adjusts caps as headcount grows or shrinksAuto-proportional to seat count

Source: Cursor Docs — Spend Limits + Cursor Blog — Organizations (retrieved 2026-06-05). Enterprise plan required for pooled usage.

05Identity & ProvisioningSSO and SCIM, configured once.

The identity story is where Cursor's tiering quietly diverges from the competition. Per Cursor's docs, SAML 2.0 SSO is available on both Teams and Enterprise plans at no additional cost, with support for Okta, Azure AD, Google Workspace, and OneLogin, plus Just-in-Time provisioning so new users auto-enroll on first SSO login. SCIM 2.0 provisioning is available on Enterprise plans with SSO enabled — access is granted when an employee joins a designated IdP group and revoked when they leave, with directory groups and memberships syncing in real time.

That SCIM-to-Groups link is what makes the segmentation model durable rather than a one-time spreadsheet exercise. When a marketer moves into a product role in your identity provider, their Cursor group membership — and therefore their model access and budget — follows automatically. Governance that drifts the moment HR makes a change is not governance; the real-time directory sync is the part that keeps the policy honest.

Where SSO enters each vendor's tier ladder

Source: Cursor Pricing + GitHub Copilot Plans (retrieved 2026-06-05)
Cursor — SSO entry tierSAML/OIDC SSO included on Teams plan
Teams
GitHub Copilot — SSO entry tierSAML SSO reserved for Enterprise plan
Enterprise
GitHub Copilot Business — SSONo SAML SSO at the Business tier
None
The under-reported gap
Cursor includes SAML/OIDC SSO on its Teams plan; GitHub Copilot reserves SAML SSO for Enterprise, and its Business tier has none. For a mid-market team that wants single sign-on without negotiating an enterprise contract, that is a real, concrete difference — and one no vendor blog has put side by side.

06The Trade-OffWhen access conflicts, the most permissive setting wins.

Here is the design decision security teams should read twice. Cursor's blog documents that when a user belongs to multiple teams or groups, the most permissive setting wins. A user who sits in both a restricted marketing group and a permissive engineering group inherits the higher-access configuration. This is documented for the settings Cursor's announcement describes; we are not extrapolating it to every control in the product.

For convenience, the rule is sensible — it stops a contributor from being silently locked out of a model their other group grants. But it runs directly counter to the least-privilege principle that governs most enterprise security programs, where overlapping memberships should resolve to the tightest permission, not the loosest. Cursor chose velocity; a default-deny posture would have chosen lock-down. Naming that explicitly is the kind of analysis no vendor blog will publish — and it is the first thing your security reviewer will ask about.

Governance watch-out
The "most permissive setting wins" rule, as documented for the settings Cursor names, is a deliberate velocity choice — not a least-privilege one. Before you trust the defaults, audit which users hold overlapping group memberships and confirm the resolved access is what your policy intends. Where strict least-privilege is mandatory, treat group overlap as something to manage tightly, not assume away.

This is also the cleanest point of contrast with GitHub Copilot's governance model, which is built to cascade down: enterprise owners set policies and can delegate to org owners, with the framework designed so control flows from the top. Two products, two opposite instincts about how permissions should resolve under conflict. Neither is wrong in the abstract — but a regulated enterprise and a fast-moving startup will not pick the same one.

07The Head-to-HeadCursor Organizations vs GitHub Copilot Enterprise.

The timing is not a coincidence. GitHub launched the Copilot App in technical preview on June 2, 2026, and moved Copilot to usage-based billing on June 1 — the same week Cursor shipped Organizations. Putting both on one timeline makes the implication clear: these two are in a direct enterprise-governance race, and the battleground is admin control, not model quality. The matrix below maps the governance surface across both platforms.

Governance feature matrix comparing Cursor Teams, Cursor Enterprise with Organizations, GitHub Copilot Business, and GitHub Copilot Enterprise.
Governance dimensionCursor TeamsCursor Enterprise + OrganizationsCopilot BusinessCopilot Enterprise
SAML SSO includedYes (no extra cost)YesNoYes
SCIM provisioningEnterprise onlyYes (with SSO)Via Enterprise CloudYes (Enterprise Cloud)
Per-unit budgetsTeam-levelGroup / team / org (most specific wins)User-level credit budgetsUser / cost-center / enterprise (lowest headroom wins)
Model access controlsLimitedPer-group, function-basedModels policyModels policy (delegable)
Policy cascade directionTeam settingsMost permissive wins (documented settings)Inherits enterpriseCascades down / delegable
Audit logsDashboard metricsEnterprise audit logsLimitedYes

Source: Cursor Pricing + Docs (SSO, SCIM, Spend Limits, Dashboard); GitHub Copilot Plans + Docs (Policies, Budgets). Retrieved 2026-06-05.

Two contrasts do the analytical work. First, the SSO entry tier: Cursor democratizes single sign-on down to its Teams plan, while Copilot gates SAML SSO behind Enterprise. Second, the budget interaction rule: Cursor resolves to the most specific limit, Copilot to the lowest remaining headroom. The first favors mid-market buyers; the second is a genuine philosophy difference your finance team should pressure-test against its own forecasting model. For teams still weighing whether to extend an incumbent like Copilot or adopt a new-category IDE, this matrix is exactly the input that the build vs. buy decision hinges on.

08Why NowThe governance layer is a retention play.

Organizations did not appear because Cursor suddenly cared about admin consoles. It appeared because the revenue mix demanded it. TechCrunch reported in April 2026 that Cursor crossed $2B ARR in February 2026, with enterprise revenue growing from roughly a quarter of the total in late 2024 to about 60% at the $2B milestone. Fortune, reporting independently in March 2026, profiled the same enterprise surge. When most of your money comes from large organizations, governance tooling stops being a feature and becomes the thing that keeps the contract.

The product, in other words, has been rebuilt around enterprise needs as enterprise grew — it was not architected this way from day one. That reframing matters for buyers: Organizations is the expansion and retention mechanism for the segment that already pays Cursor's bills, which is exactly why it is comprehensive on budgets and access but comparatively young on the hardest least-privilege controls. Vendor coverage frames this as a feature launch; the more useful frame is that it is a defensive move in a market the CEO himself describes as consolidating.

"It's pretty clear the market is standardizing on a couple solutions. It's a narrow field of folks really at scale here."— Michael Truell, CEO, Cursor / Anysphere

There is a practical "why now" underneath the strategic one. Industry coverage in early June framed the moment as a tokenomics reckoning: the spend controls and pricing changes that landed alongside Organizations are, in part, a response to enterprise customers who could not forecast their AI bills. Read that way, Organizations is not only about who can use which model — it is about giving finance a way to put a hard ceiling on a line item that had been growing unpredictably. That is a real adoption unlock, and it is the part of the story most feature write-ups skip.

On the market-share picture
Treat developer-adoption survey figures with care. Independent surveys circulating in early 2026 suggest GitHub Copilot still leads in day-to-day work usage while Cursor leads in developer awareness — but the precise percentages reach us through secondary aggregators, so we report the direction, not the decimals. What is well-corroborated is the enterprise-revenue trajectory and the roughly two-thirds Fortune 500 reach, cited below.

09What To DoA decision tree for real rollouts.

Organizations changes the calculus for a few specific buyer profiles and leaves the rest unchanged. Here is the honest version of who should move and who should wait.

Large Cursor footprint
Multi-team enterprises already on Cursor

If you run Cursor across several departments, Organizations is a clear upgrade: one dashboard, per-team budgets, and SCIM-driven model segmentation replace a sprawl of loosely-governed team accounts. Adopt it, then audit overlapping group memberships first.

Adopt Organizations
Mid-market, SSO-led
Teams that need SSO without an enterprise contract

Cursor includes SAML/OIDC SSO on its Teams plan; Copilot gates it behind Enterprise. If single sign-on is your gating requirement and you're not ready for an enterprise deal, Cursor's tier ladder is the more democratic path.

Lean Cursor Teams
Least-privilege mandate
Regulated orgs under strict access control

If NIST AC-6 or ISO 27001 least-privilege is non-negotiable, the documented 'most permissive wins' resolution needs scrutiny. Copilot's top-down policy cascade may map more naturally to your control framework — pilot both and test conflict resolution explicitly.

Evaluate both, test conflicts
Cost-forecasting pain
Finance can't predict the AI bill

The new three-tier spend hierarchy plus dynamic headcount scaling is built for exactly this. Stand up group and team caps before frontier fast-mode access is granted broadly — set the ceiling first, expand access second.

Set caps before access

For everyone running a single small team, the change is marginal — Organizations is an enterprise-scale answer to an enterprise-scale problem. The right move for most organizations is to pilot the governance model against a real policy: assign a finance group with a hard cap, an engineering group with frontier access, and one user in both, then watch how the access resolves. That single test tells you more than any feature list. The same competitive context plays out in the broader IDE field — see our read on Windsurf's migration to Devin Desktop and the underlying agent layer in Cursor 3's agent-first architecture, which is what Organizations is ultimately built to govern.

10ConclusionThe AI coding race moved to the admin console.

The shape of enterprise AI coding, June 2026

Capability got commoditized — control is the new battleground.

Cursor Organizations is less a feature launch than a statement about where the market is. When the model itself is increasingly a commodity that every vendor can route to, the durable differentiator becomes the governance layer — who can use which model, on whose budget, under whose policy. Cursor built that layer because roughly 60% of its revenue now depends on it, and it shipped the same week GitHub answered with its own desktop and billing moves.

The honest assessment: Organizations is genuinely strong on the things enterprises asked for loudest — per-team budgets, function-based model segmentation, SCIM-driven Groups, and SSO that reaches further down the tier ladder than its rival's. It is not a least-privilege-first design, and the documented "most permissive wins" rule is the trade-off a careful security reviewer will flag first. Both things are true at once.

The broader signal is the one worth carrying forward: enterprise adoption of AI coding has crossed from experimentation into standardization, and standardization is governed, budgeted, and audited. The teams that win the next year will not be the ones with the cleverest autocomplete. They will be the ones that put a defensible policy around it — model access by function, spend caps that finance trusts, and a conflict-resolution rule they actually chose on purpose rather than inherited from a default.

Govern AI coding without slowing engineering down

Put a defensible policy around AI coding before you scale it.

We help engineering and operations teams roll out governed AI coding — model-access policy by function, spend caps finance trusts, SSO and SCIM wired to your identity provider — across Cursor, Copilot, and the rest of the agentic stack.

Free consultationExpert guidanceTailored solutions
What we work on

AI coding governance engagements

  • Model-access policy by function across teams
  • Spend-cap design finance can actually forecast
  • SSO + SCIM wired to your identity provider
  • Cursor vs Copilot enterprise evaluation on your stack
  • Least-privilege review of group / permission overlap
FAQ · Cursor Organizations guide

The questions we get every week.

Cursor Organizations is an enterprise governance layer that Cursor announced on June 3, 2026, generally available to its Enterprise customers. Per Cursor's own announcement, it is a top-level container that gives admins one dashboard to manage multiple Cursor teams, view a rollup of spend and token usage across the company, and configure security, governance, budget, and feature settings for each team. The structure is three layers deep — Organization, Teams, and Groups — and the launch arrived the same week Cursor restructured its Teams pricing. It is distinct from the general software concept of an 'organization': this is a specific, capitalized product feature.