need to check that the user associated with the request actually has an organization_id attribute (there are certain cases, such as if the request.user is a "django user" where this attribute would not be present)