Adding a user
Why this is always an invitation, and what a
201 does not promise.Groups
Organization policies and account role assignments for a team of users.
Removing a user
What it detaches, what it leaves behind, and when it takes effect.
Adding a user
- Console
- API
- CLI
- Go
Open Organization → Users, then Invite users. Enter one or
more Email addresses and optionally select Groups. Each address
receives its own invitation; the results show which invitations succeeded.Pending invitations are listed on the Users page with a
Cancel invitation action.
email is the only required field. groups is the useful one: it puts the
person in their groups at the moment they join, so there is no window where
they exist with no permissions and someone has to remember to fix it.
This call always creates an invitation, never a user. The response is the
invitation, and the person becomes a user when they accept it — including
when they already have a Basaltic login. There is no path that adds someone
to an organization without their consent.Until they accept they are a row on the pending-invitations list, not on
Users.
409 in two cases, which are worth telling apart:
Invitations
An invitation records its actual inviter.invited_by.type distinguishes a
user, service account, or assumed-role session; machine inviters also include
their account identity and do not have a human email address.
An invitation is the pending half of the call above. There is no separate
“create invitation” endpoint on the public API — you add a user, and an
invitation is what you get when they do not exist yet.
- Console
- API
- CLI
- Go
Pending invitations are listed on Organization → Users, below the users, with
Cancel invitation on each row. When there are none the section reads
“No pending invitations.”
Groups
A group collects principals and holds policies. Attaching a policy to a group rather than to each member is the difference between one change and n changes when the team’s permissions move.- Console
- API
- CLI
- Go
Open Organization → Groups and choose Create Group. Enter
a Name and an optional Description.The group’s Users and Policies tabs manage its user members and
organization policy attachments.
Where to attach a policy
Attach organization policies to groups when the grant describes a team or job. Use direct user attachments for individual exceptions. Account permissions belong on roles and service accounts, not on users or groups. Inline policies are a third option and a narrower one — see managed and inline policies.Removing a user
- Console
- API
- CLI
- Go
Open the user, choose Settings, then Remove user in the danger
zone. Type the displayed confirmation value before confirming.
Permissions
These APIs usehttps://workspace.basaltic.sh. Their actions are in the
workspace: namespace and must be granted through organization policies.
See Workspace permissions for the resource checks
and account role assignment actions.
Next
Service accounts and roles
The identities that are not people.
Writing policies
What goes in the document you attach here.