Skip to content

Docs / 10 of 14

Teams and permissions

Membership roles owner, admin, member, and billing; invites; last-owner rules; SSO and SCIM status. Unlimited seats. For workspace admins on nox.markets.

3 min read

A User is global. Access to an Organization is a Membership with a role. Unlimited seats on every tier. There is no seat field at checkout.

Manage the roster at /dashboard/team.

Roles

MemberRole values are owner, admin, member, and billing.

billing is not a higher member. It is a side channel: invoices and plan changes, not product runs.

Capabilityowneradminbillingmember
Read catalog and Entitlementsyesyesyesyes
Run or use entitled productsyesyesnoyes
Invite or remove members, change rolesyesyesnono
Create or revoke API keysyesyesnono
Connect or revoke integrationsyesyesnono
View invoices, change plan, checkoutyesyesyesno
Delete Organization, transfer ownershipyesnonono

member can run and configure products they are entitled to use. They cannot connect new OAuth apps, change retention, or see billing.

Custom permission sets (product.run, integration.connect, and the rest) are a scale design. Not yet available in this build. Use the four roles above.

Invite

owner or admin only. Cap: 25 invitations per day per Organization.

  1. /dashboard/team → Send invite.
  2. Work email and a role.
  3. The invitee gets mail from nox.markets. The token is emailed once and never stored in plaintext. It is not returned by the API.
  4. They sign in with that address and accept at /invite/[token].

One pending invite per email per Organization. Re-inviting revokes the previous pending row.

Confirmations and errors:

  • Invite sent to {email}.
  • You are in {workspace}.
  • This invite is expired or already used. Ask the admin to send another.
  • This invite is for {email}. Sign in with that address.

Empty roster: Only you. Invite the person who actually approves the bills.

Accepting is not “using up a licence.” Plans do not charge per seat.

Change role or remove

PATCH role from the roster. DELETE removes the Membership (deletedAt soft-delete).

The last owner cannot be demoted or removed (409 last_owner). Transfer ownership first.

Removing a person does not revoke Organization ApiKey rows. Keys belong to the Organization, not the person, and survive. Revoke keys separately if that person also held a copied secret.

Sessions for a removed user no longer include that Organization. They may still belong to other Organizations.

Sign-in, SSO, SCIM

  • Password, Google OAuth, and Microsoft OAuth: all tiers, including starter. Password accounts require MFA. IdP MFA is accepted for SSO accounts; we do not add a second factor on top.
  • Session: 7-day idle, 30-day absolute.
  • SAML 2.0 (growth+): Not yet available in this build.
  • Forced SSO (password disabled): Not yet available.
  • SCIM 2.0 (scale+): Not yet available. Designed behavior: create/deactivate users and group→role mapping. Deprovisioning revokes sessions; it does not delete runs or configuration.
  • IP allowlist (growth+): Not yet available.

Multiple Organizations

A User can hold Memberships on more than one Organization. The session has one activeOrgId. Switch active org from the workspace switcher (POST /api/me/active-org). Routes that name an orgSlug you do not belong to return 404, not 403.

Plan workspace caps (starter 1, growth 3, scale 10) apply when extra-workspace creation is enforced. Until that limiter ships, do not treat extra Organizations as included in starter.

Audit

Role changes, invites, and removals write an AuditLog row (actor, IP, redacted diff). Retention: 30 days on starter, 12 months on growth, 36 months on scale. CSV/JSON export of the audit log from the dashboard is growth+. SIEM streaming is scale+ and Not yet available in this build.

Next