Who can do what.
WHAT THE MODEL USUALLY NEEDS
An organisation or workspace Users belonging to it Roles determining permissions Invitations
WHY THE ORGANISATION IS THE UNIT
Billing, data and permissions attach to it rather than to an individual.
WHAT HAPPENS WITHOUT THAT
The account belongs to whoever signed up, and the business loses it when they leave.
WHAT TO BUILD EARLY
Ownership that can be transferred.
WHAT ROLES ARE USUALLY SUFFICIENT
An owner Administrators Ordinary members A read-only role
WHY READ-ONLY MATTERS
It is requested constantly, by organisations wanting oversight without risk.
WHAT INVITATIONS REQUIRE
An email, a role, and expiry Handling of someone already in another organisation
WHAT TO DECIDE
Whether a person can belong to several organisations.
WHY DECIDE EARLY
Retrofitting it is difficult.
WHAT REMOVAL MUST HANDLE
Work assigned to that person Content they created Their access, immediately
WHAT TO NEVER DO
Delete their contributions with them.
WHAT TO LOG
Every change to membership and permissions.
WHAT TO PROVIDE ADMINISTRATORS
A view of who has access to what.