Skip to main content

Members & roles

Membership determines who belongs to an organization. Roles and permissions determine what those members can do. Starfire keeps these concepts separate so joining an organization does not automatically grant administrative access to everything it owns.

Invitations

Authorized organization administrators can invite a person to join the organization with an intended role. Before sending an invitation, confirm:
  • the correct account or email identity
  • the organization
  • the intended role
  • whether the person needs billing or developer access
  • whether a seat or plan restriction applies
An invitation should not grant more access than the role assigned to it.

Role model

A role is a reusable permission bundle. Organization roles can distinguish normal member access from more sensitive capabilities such as:
  • member administration
  • project administration
  • Knowledge management
  • billing visibility or changes
  • developer credentials
  • organization settings
  • policy changes
Exact role names can vary as Organizations 3.0 evolves.

Least privilege

Give members the smallest role that lets them do their job. A developer who needs to work on an organization project does not automatically need subscription-management rights. A billing administrator does not automatically need developer credentials.

Membership changes

When a member changes responsibilities:
  1. Review their current role.
  2. Remove permissions no longer required.
  3. Transfer ownership of any personal resources that should become organization-owned where supported.
  4. Review developer keys, service accounts, or integrations associated with the person.
  5. Review active sessions or security concerns when appropriate.

Removing a member

Removing a member should end their organization access without deleting the organization’s resources. Organization-owned projects, Knowledge bases, applications, usage history, and billing records should remain attached to the organization.

Platform vs organization roles

Organization roles control team resources. Control Center RBAC controls platform-wide administration. Do not use a platform-admin role to solve an organization membership problem.
Administrative access should be reviewed whenever a member leaves the organization. Removing membership does not automatically prove that every independent developer credential or external integration owned by that person has been revoked.

Permissions & policies

Understand inherited access, overrides, and organization-level policy controls.