Docs / 10 of 14
Teams and permissions
Membership roles owner, admin, member, and billing; invites; last-owner rules; SSO and SCIM status. Unlimited seats. For workspace admins on nox.markets.
A User is global. Access to an Organization is a Membership with a role. Unlimited seats on every tier. There is no seat field at checkout.
Manage the roster at /dashboard/team.
Roles
MemberRole values are owner, admin, member, and billing.
billing is not a higher member. It is a side channel: invoices and plan changes, not product runs.
| Capability | owner | admin | billing | member |
|---|---|---|---|---|
| Read catalog and Entitlements | yes | yes | yes | yes |
| Run or use entitled products | yes | yes | no | yes |
| Invite or remove members, change roles | yes | yes | no | no |
| Create or revoke API keys | yes | yes | no | no |
| Connect or revoke integrations | yes | yes | no | no |
| View invoices, change plan, checkout | yes | yes | yes | no |
| Delete Organization, transfer ownership | yes | no | no | no |
member can run and configure products they are entitled to use. They cannot connect new OAuth apps, change retention, or see billing.
Custom permission sets (product.run, integration.connect, and the rest) are a scale design. Not yet available in this build. Use the four roles above.
Invite
owner or admin only. Cap: 25 invitations per day per Organization.
/dashboard/team→ Send invite.- Work email and a role.
- The invitee gets mail from
nox.markets. The token is emailed once and never stored in plaintext. It is not returned by the API. - They sign in with that address and accept at
/invite/[token].
One pending invite per email per Organization. Re-inviting revokes the previous pending row.
Confirmations and errors:
- Invite sent to {email}.
- You are in {workspace}.
- This invite is expired or already used. Ask the admin to send another.
- This invite is for {email}. Sign in with that address.
Empty roster: Only you. Invite the person who actually approves the bills.
Accepting is not “using up a licence.” Plans do not charge per seat.
Change role or remove
PATCH role from the roster. DELETE removes the Membership (deletedAt soft-delete).
The last owner cannot be demoted or removed (409 last_owner). Transfer ownership first.
Removing a person does not revoke Organization ApiKey rows. Keys belong to the Organization, not the person, and survive. Revoke keys separately if that person also held a copied secret.
Sessions for a removed user no longer include that Organization. They may still belong to other Organizations.
Sign-in, SSO, SCIM
- Password, Google OAuth, and Microsoft OAuth: all
tiers, includingstarter. Password accounts require MFA. IdP MFA is accepted for SSO accounts; we do not add a second factor on top. - Session: 7-day idle, 30-day absolute.
- SAML 2.0 (
growth+): Not yet available in this build. - Forced SSO (password disabled): Not yet available.
- SCIM 2.0 (
scale+): Not yet available. Designed behavior: create/deactivate users and group→role mapping. Deprovisioning revokes sessions; it does not delete runs or configuration. - IP allowlist (
growth+): Not yet available.
Multiple Organizations
A User can hold Memberships on more than one Organization. The session has one activeOrgId. Switch active org from the workspace switcher (POST /api/me/active-org). Routes that name an orgSlug you do not belong to return 404, not 403.
Plan workspace caps (starter 1, growth 3, scale 10) apply when extra-workspace creation is enforced. Until that limiter ships, do not treat extra Organizations as included in starter.
Audit
Role changes, invites, and removals write an AuditLog row (actor, IP, redacted diff). Retention: 30 days on starter, 12 months on growth, 36 months on scale. CSV/JSON export of the audit log from the dashboard is growth+. SIEM streaming is scale+ and Not yet available in this build.
