Group-memberships (teams) management

A team manager creates an invitation. The invitee previews its code with resource context and accepts it using their own active identity. Those are separate permissions and outcomes; a team listing is not a management grant.

Value / actorMeaningUsed by
Team ID 1001Team recordTeam list/management/invitation path.
Member user IDPerson recordTeam membership management; never substitute a relationship ID.
Team relationship IDUser↔team relationshipInternal linkage distinct from user/team IDs; activation creates or updates it.
Invite ID 3001Managed invitation recordInvite management; not the code accepted by invitee.
Returned invite codeRedeemable invitation inputValidation and activation body invite; not a member token.
Pricing ID 2001 / subscription_idConfigured publisher PricingInvitation eligibility/membership selection; each Plan has many Pricings. Not an existing membership ID.
Manager tokenExisting member context with action eligibilityCreate/manage intended team invitations.
Invitee tokenIntended recipient’s active member contextActivation; determines comparison email.
Resource keySelected resource contextValidation scope and invite creation storage; not an identity credential.

What does each step establish?

  1. List teams as the manager. An owner/admin role selects list rows, even without active/status/resource filtering. Check action eligibility before changing a team.
  2. Create invitation for reader@example.com and an eligible free Pricing. Retain returned invite ID and generated code separately. HTTP 201 describes a record and attempted queue event, not delivered email or reserved seat.
  3. Validate code under the issuer’s resource. The code, window, cap and conditional email/domain/team-capacity checks can pass without identity when no email is supplied. Use intended email, but do not call it verified ownership.
  4. Activate with reader@example.com’s active member context. Checks run again; writes can attach/reactivate team and conditionally replace/create memberships. Team-linked result has subscription_id:null. Paid invite Pricing has no active checkout branch; result:true does not prove entitlement/payment.
Diagram of What does each step establish?
Open full diagram · Read diagram text
flowchart TD
    M[Manager with action eligibility] --> C[Create invite record]
    C --> Q[Attempt invitation queue event]
    C --> V[Invitee previews supplied code]
    V -->|Valid now| I[Resolve intended active member]
    I --> A[Activate code]
    A --> T[Attach or reactivate team relationship]
    A --> P[Conditional membership writes]
    A --> R[Return activation result]

The queue arrow is an attempt, not a delivered-mail guarantee. Preview does not reserve capacity, consume activation or sign in a person.

Activation looks up the code separately, without the earlier resource filter. If codes collide, it can select a different invite from validation. Some writes are not checked, database transactions can be nested, and external events can fail separately. Do not assume all changes succeed together or that retrying is safe. Membership replacement can affect existing account/sponsorship relationships. Request a separate content-access decision when needed.

Choose a team-management task

NeedOperationMeaning
Create a company teamCreateSaves team/owner; no Pricing purchase, invitation or partner link automatic.
Change name/description/typeUpdateThe reviewed source does not establish that this operation completes successfully. A change can be saved before it fails. Capacity, Pricing, active and never_lock changes are ignored.
Inspect associated users/invitesDetailAll relationships, not a guaranteed active/resource-filtered view; check returned ID.
Inspect invitation usageInvite listPaged records with count/used, no delivered-mail/available guarantee.
Inspect one invite/codeInvite detailRecord must belong to selected team.
Delete intended team recordDeleteBoolean model-delete outcome, no universal dependent cleanup/refund/user deletion.

Edit, remove or resend an invitation?

TaskStart hereWhat remains separate
Change recipient/title/PricingUpdate inviteNo active resend; email/domain checks differ from creation.
Delete invite recordDelete inviteNo member/membership removal or email recall.
Send another notification attemptMember-route resendNo usage/window/domain/capacity reset or delivery guarantee.
Use admin-prefix credential resolutionAdmin-prefixed resendSame action/user ACL and guards; prefix alone is not admin permission.

Change team participation without deleting the person

NeedStart hereMeaning / limit
List non-owner peopleMember listNo returned role/status expansion; removed/suspended rows can appear.
Inspect one linked person’s accountMember detailResource memberships/partner teams, not only selected-team state.
Change role or statusUpdate memberCan demote owner without last-owner guard. New Pricing assignment reaches disabled checkout; role/status attempt precedes it.
Mark removedRemoveKeeps person/relationship, changes status; owner guard requires another owner role, not active replacement.
Mark suspendedSuspendKeeps records, changes status; no global user suspension or refund.

Removal, suspension, invite deletion and team deletion have different effects. These status routes do not explicitly delete existing memberships or revoke all content access. Renewal handling can skip nonactive team relationships; request the separate access decision when serving content. Ticket/pass and sponsored-slot workflows are separate jobs; these IDs and permissions are not substitutes for their credentials.

Full diagram

Use the arrow keys to scroll. Escape closes this view.

Search documentation

Enter at least 2 characters.

    ↑ ↓ move through results · Enter opens · Escape closes