For organizations
What differs on an org install
An org install is arkush on a server that one organization runs for its own people. It runs the same app as arkush.app, with different settings. This page lists each difference that a person meets in the app. A section of a guide that only an org install offers carries the note Org installs only.
An organization gets an org install under a licence. The settings of each org install are its own, so an org install can leave out a feature that this page names. To learn which features your org install has, ask the people who run it.
Sign-in
- On arkush.app: anyone signs in with a Google or a GitHub account, or with a code sent to their email, and can come back with a passkey.
- On an org install: the people of the organization sign in, most often with the organization's own Google accounts. The sign-in page names the accounts it takes.
Sharing
- On arkush.app: a dashboard is private or published to the internet. Only the people who run arkush.app add a share, and there is no way to ask them for one. Publish the dashboard, or send it as a file: see Share a dashboard.
- On an org install: you share a dashboard with people and groups, with View or Edit access, and you can open it to everyone signed in. See Share a dashboard. Publishing to the internet is off unless the org install turns it on.
BigQuery
- On arkush.app: a query runs in your browser, under your own Google account, and bills a Google Cloud project that you choose. Only a person refreshes it.
- On an org install: a query can also run on the server as a service account: a Google account for a program, which the people who run the org install register by name. A person runs a query as that account only when Google grants them the Service Account User role on it. A schedule and an AI agent then refresh the query. The org install can set a default billing project. An agent can also list the warehouse's datasets and tables as a service account. See Query BigQuery as a service account.
Google Sheets and files at an address
- On arkush.app: your browser reads a sheet or a file that Google hosts, and the server reads nothing at an address. You refresh it with Refresh.
- On an org install: the server can also read published sheets and files at an address, and a private sheet with its own Google account, so the schedule keeps them fresh. A person with the analyst right sets up the private-sheet read: see A private Google Sheet on the schedule.
Databases
- On arkush.app: no datasource reads a database.
- On an org install: a datasource can run its SQL on a PostgreSQL database the server connects to, as a service account, when the people who run the server registered the database. See Query a database.
Scheduled sends to Slack
- On arkush.app: not available. Subscribe says that subscriptions come with an org install, and offers Join the waitlist.
- On an org install: a person subscribes to a dashboard and gets its charts in their Slack direct messages. An editor can also schedule a delivery to a Slack channel in the Deliveries section at the end of the Data panel. A person with the analyst right selects Send now on the delivery once, and the schedule runs it after that. See Read a dashboard.
Sandboxes
- On arkush.app: a sandbox is a private layer of your own charts over a dashboard that you can view but not edit. It needs a dashboard that was shared with you, and only the people who run arkush.app share, so most people on arkush.app never meet one.
- On an org install: a person who can view a dashboard but not edit it adds charts of their own in a sandbox. See Add a chart of your own in a sandbox.
Rights and administration
- On arkush.app: the people who run arkush.app hold the analyst right and the admin right. They curate the datasource library and the theme library.
- On an org install: the people who run it give the analyst right and the admin right to named people or to groups. A person with the analyst right curates the datasource library on the Datasources page and the theme library in the theme editor's Library group, and stamps a dashboard Official. An admin manages groups, agents and access. An admin can also limit who connects an AI agent, and who takes rows away: data as a CSV file, an exported dashboard, the tables in a scheduled send, and the rows an agent reads. See Administer an instance.
Stored files
- On arkush.app: you keep files in the files store for your own dashboards. A file stays private to you, because only the people who run arkush.app share.
- On an org install: you share a stored file with people and groups from its page, so their dashboards read it too. See Store a file for reuse.
The server's own name
- On arkush.app: the header reads arkush.
- On an org install: the header can show the organization's name or logo before arkush.
The same everywhere
Readers read saved rows and never run a query. A dashboard shows every reader the same rows. The datasource row limit, the canvas, the blocks, comments and version history work the same on arkush.app and on an org install. AI agents connect over MCP on both. On arkush.app, an agent works from the rows of your last refresh and cannot run a BigQuery query, because the server holds no warehouse access. It runs derived views and other work over the saved rows on both. See What arkush is and is not.