Skip to main content
Roles are default permission bundles. Server routes authorize explicit permissions against a concrete workspace resource; hiding a UI control or comparing a role-name string is not the security boundary. Owner assignment uses organisation.owners.manage, separate from member management. An owner must be transferred or removed through the organisation operation before ordinary membership removal. Invitations expose no workspace data until the one-time token is accepted by the invited email address.