Members and roles of a zriz org
An admin invites a person by email with zz members invite. An org has three roles: admin, member, and viewer. There is no other role.
- How do I invite a person?
- What can each role do?
- Where do I see the members and my role?
- How do I change the role of a member?
- How do I remove a member?
- How do I cancel an invite?
- What does an invited person see?
- How do I work in two orgs?
How do I invite a person?
An admin does zz members invite <email>. The invite gives the role member and stays open for 7 days.
Add --role admin or --role viewer for a different role.
The field emailed of the reply tells how the person gets the join link:
emailed |
What to do |
|---|---|
true |
Nothing. The cloud sent the join link to the address. |
false |
Give the value of link to the person. The cloud sent no email. |
A new invite for the same address revokes the invite that was open. The error already-member means that the address is a member of the org now.
What can each role do?
An admin can do each action. A member can start runs but cannot manage members or runner tokens. A viewer can only read.
| Action | admin | member | viewer |
|---|---|---|---|
| Read the runs, the runners, and the members | Yes | Yes | Yes |
| Start a run | Yes | Yes | No |
| Make or revoke a runner token | Yes | No | No |
| Invite a person, cancel an invite | Yes | No | No |
| Change a role, remove a member | Yes | No | No |
A command that the role does not permit gives the error forbidden.
Where do I see the members and my role?
zz members lists the members with their roles, and the open invites. Each role can do this command.
How do I change the role of a member?
An admin does zz members role <email> <role>. The role is admin, member, or viewer.
An org must keep one admin. A change that leaves no admin gives the error last-admin.
When an admin gets a lower role, the cloud revokes the open invites that this person made.
How do I remove a member?
An admin does zz members remove <email>. The person is no longer a member, and the cloud ends the web sessions of the person.
The API keys of the person stop at the next request. The cloud also revokes the open invites that this person made.
The last admin cannot be removed: the error is last-admin.
How do I cancel an invite?
An admin does zz members uninvite <id>. The id is the field id of the invite in the reply of zz members.
The join link of that invite then does not work.
What does an invited person see?
The join link opens a page with the heading Join <org name>. The page shows the address and asks for a new password.
The person clicks Join. The person is then signed in as a member of the org, with the role of the invite.
Two cases stop the person:
| The page says | Cause |
|---|---|
This invite link is not valid. |
The invite was used, was cancelled, or is older than 7 days. Make a new invite. |
This email already has a zriz account. |
One email belongs to one org. Ask the admin to invite a different email of yours. Then add the login: zz login --add |
How do I work in two orgs?
Use two emails. One email is one account in one org.
- Add the second login:
zz login --add --as personal. Sign in with the second email in the tab. - List the logins:
zz switch - In a work folder, the project selects the login.
.zriz/project.jsonhasorg, andzzuses the login of that org. Each command shows the org it used. - Out of a work folder,
zzuses the current login. Change it:zz switch work - For one command, use
--orgwith a login name or an org id:zz --org personal runners - For a shell, set the variable
ZZ_ORGto a login name or an org id:export ZZ_ORG=personal.--orgwins overZZ_ORG. - Rename a login:
zz switch --rename personal home - Remove one login:
zz logout personal. Remove each login:zz logout --all.
The reply of a command has the key org, with login, org-id, and source. source is flag, zz-org, project, current, only-login, or api-key-env.
A command with the wrong org stops with org-mismatch. To move a project to a different org, change org in .zriz/project.json.