zrizDocsLearnSecuritySign inSign up

Members and roles of a zriz org

An admin invites a person by email with zz members invite. An org has three roles: admin, member, and viewer. There is no other role.

Question · zz 0.4.0 or later · Updated · Plain text for agents: /docs/team.md

How do I invite a person?

An admin does zz members invite <email>. The invite gives the role member and stays open for 7 days.

Add --role admin or --role viewer for a different role.

The field emailed of the reply tells how the person gets the join link:

emailed What to do
true Nothing. The cloud sent the join link to the address.
false Give the value of link to the person. The cloud sent no email.

A new invite for the same address revokes the invite that was open. The error already-member means that the address is a member of the org now.

What can each role do?

An admin can do each action. A member can start runs but cannot manage members or runner tokens. A viewer can only read.

Action admin member viewer
Read the runs, the runners, and the members Yes Yes Yes
Start a run Yes Yes No
Make or revoke a runner token Yes No No
Invite a person, cancel an invite Yes No No
Change a role, remove a member Yes No No

A command that the role does not permit gives the error forbidden.

Where do I see the members and my role?

zz members lists the members with their roles, and the open invites. Each role can do this command.

How do I change the role of a member?

An admin does zz members role <email> <role>. The role is admin, member, or viewer.

An org must keep one admin. A change that leaves no admin gives the error last-admin.

When an admin gets a lower role, the cloud revokes the open invites that this person made.

How do I remove a member?

An admin does zz members remove <email>. The person is no longer a member, and the cloud ends the web sessions of the person.

The API keys of the person stop at the next request. The cloud also revokes the open invites that this person made.

The last admin cannot be removed: the error is last-admin.

How do I cancel an invite?

An admin does zz members uninvite <id>. The id is the field id of the invite in the reply of zz members.

The join link of that invite then does not work.

What does an invited person see?

The join link opens a page with the heading Join <org name>. The page shows the address and asks for a new password.

The person clicks Join. The person is then signed in as a member of the org, with the role of the invite.

Two cases stop the person:

The page says Cause
This invite link is not valid. The invite was used, was cancelled, or is older than 7 days. Make a new invite.
This email already has a zriz account. One email belongs to one org. Ask the admin to invite a different email of yours. Then add the login: zz login --add

How do I work in two orgs?

Use two emails. One email is one account in one org.

  1. Add the second login: zz login --add --as personal. Sign in with the second email in the tab.
  2. List the logins: zz switch
  3. In a work folder, the project selects the login. .zriz/project.json has org, and zz uses the login of that org. Each command shows the org it used.
  4. Out of a work folder, zz uses the current login. Change it: zz switch work
  5. For one command, use --org with a login name or an org id: zz --org personal runners
  6. For a shell, set the variable ZZ_ORG to a login name or an org id: export ZZ_ORG=personal. --org wins over ZZ_ORG.
  7. Rename a login: zz switch --rename personal home
  8. Remove one login: zz logout personal. Remove each login: zz logout --all.

The reply of a command has the key org, with login, org-id, and source. source is flag, zz-org, project, current, only-login, or api-key-env.

A command with the wrong org stops with org-mismatch. To move a project to a different org, change org in .zriz/project.json.