Organizations, members, roles and invitations
Create an organization, invite people with a one-time link, accept an invitation, change roles, remove members and hand over ownership in Beyond Accounts.
- Availability: Experimental
- Evidence: Read from source
- How-to guide
Before you start
You must be signed in to Beyond Accounts. To invite, change roles or remove people you must be Owner or Administrator of the organization; other members see the list and cannot change it.
An organization in Accounts decides membership only. It does not give anyone a seat, a project or a permission in a product: see what an organization does not grant before you invite someone expecting them to be able to work in Delegate.
Roles
| Role | The interface describes it as | What it means for membership |
|---|---|---|
| Owner | "Everything, including ownership itself." | Everything an Administrator does, plus making someone an Owner, changing an Owner's role, removing an Owner and inviting as Owner |
| Administrator | "Membership and invitations." | Invites people, changes the roles of non-owners, removes non-owners, withdraws invitations |
| Developer | "A member who works here." | Sees the member list |
| Viewer | "Reads." | Sees the member list |
Products read these four roles and apply their own rules to them. Accounts itself attaches no product permission to any of them.
Create an organization
- Open Organizations and choose Create organization. With no organization yet, the screen says "You are not in an organization yet" and "Create one, or accept an invitation someone sends you. You can use your account without one."
- In Create an organization, fill in Name, up to 120 characters.
- Choose Create. Cancel keeps nothing.
Expected outcome: the organization opens with "Organization created. You own it.", and you are its Owner. An organization always has at least one owner, from the moment it exists.
Invite someone
- Open the organization and choose Invite member.
- In Invite someone, fill in Email address. The help text is the rule: "They must sign in with this address, confirmed by their provider, to accept."
- Choose a Role. The default is Developer. Owner is offered only when you are an Owner.
- Choose Invite member.
- The dialog Invitation link opens with the text "This link is shown once and is not stored. Copy it now and send it to {email}." Choose Copy (it changes to Copied), then Close.
- Send the link to that person yourself, by a channel you trust.
After you close the dialog, the page confirms "Invitation created. It waits until the link is used or expires."
The panel Invitations ("An invitation is for one address, expires, and can only be used once.") lists each invitation with its role, "Expires {date}" and a state: Waiting, Accepted or Withdrawn. To cancel one that is still Waiting, choose Withdraw. An accepted invitation cannot be withdrawn; remove the member instead.
Accept an invitation
- Open the link you received. The screen is titled "Join {organization}" and says "You have been invited as {role}." and "Sign in with {email} to accept this."
- If you are not signed in, choose Sign in to accept and sign in with a method whose address is the invited one and is confirmed by the provider. After signing in you land on Overview: open the invitation link again. The invitation is still waiting.
- Choose Accept invitation.
Expected outcome: the organization opens and you are a member with the invited role.
An invitation is accepted once. If the same link is used at the same moment from several places, one acceptance becomes a membership and the others are refused.
| You see | Meaning | What to do |
|---|---|---|
| "That invitation is not valid." | The link is unknown, incomplete, expired, already used or withdrawn. The screen does not say which, so the link cannot be used to probe | Ask an Owner or Administrator for a new invitation |
| "That invitation has expired. Ask for a new one." | It expired between opening the screen and accepting | Ask for a new one |
| "That invitation was already used or withdrawn." | Someone accepted or withdrew it in the meantime | If it was not you, ask for a new one |
| "Sign in with the address this invitation was sent to, confirmed by your provider." | Your account has no confirmed sign-in method with the invited address | Sign in with that address, confirm it, or ask for an invitation to the address you do use |
Change a role or hand over ownership
- Open the organization. In Members, each active member has a role selector.
- Choose the new role. It is saved at once.
Expected outcome: "Saved."
To hand over ownership, an Owner gives the role Owner to another member. There is no separate transfer control: an organization may have several owners, and the first owner may then change their own role.
| You see | Meaning |
|---|---|
| "An organization keeps at least one owner. Make someone else an owner first." | The change would leave the organization without an Owner. This last-owner protection applies to changing the role of the last Owner and to removing them |
| "You do not have access to this." | You are an Administrator and tried to grant, change or remove ownership. Only an Owner does that |
Rename an organization
Owners and Administrators see a Settings panel at the end of the organization page: "Renaming changes what people read, here and in every product."
- Edit Name, up to 120 characters.
- Choose Save. The button is available only after the name changes.
Expected outcome: "Saved." The name changes wherever people read it. The identifier of the organization, the org_… value that products store, never changes, so nothing a product recorded is affected.
Remove a member, or leave
- In Members, choose Remove on the person's row.
- Confirm in the dialog, which says "They lose their membership of this organization. What they did here stays readable." The dialog names the person by their account identifier, the
acc_…value shown under their name.
Expected outcome: "Saved." The person stays in the list with the tag Removed, because who worked in an organization remains readable. Products learn about the removal and apply their own consequences: see what products do.
What an organization does not grant
- Membership of an organization does not give a Delegate seat, a Delegate project or any Delegate permission. Delegate has its own workspaces, seats and per-project access. A Delegate that is not connected to Beyond Projects does not read your Accounts organizations at all; a connected one reads them as you arrive, only so that a workspace administrator can link the workspace to an organization they own or administer, and that link still gives nobody a seat or a permission. See Workspace and collaboration in Delegate.
- The organization you select as Working in is context for products that use it. It is never a grant.
- Signing in with GitHub gives Beyond no right over your repositories.
Account, organization and product workspace explains the three side by side.
Next action
Invited your team? Tell each person to accept with the invited address, then set up what they need inside the product itself.
Related: Identity and resource permissions · Sessions and signing out · Accounts troubleshooting