Managed delivery artifact
Add team invitations
Original request
Add team invitations so workspace owners can invite teammates by email.
Clarifying questions
- Should only workspace owners be able to invite teammates?
- Should invites expire?
- Should revoked invites be blocked even if the email link is still open?
- Should a new user be able to create an account from the invite link?
Approved scope
Build owner-only workspace invites with pending, accepted, revoked, and expired states. Include invite acceptance for new users, workspace settings UI updates, permission checks, tests, and documentation.
Delivery plan
- Add invitation data model and lifecycle states
- Add owner-only invite creation from workspace settings
- Add invite acceptance route
- Enforce revoked and expired invite handling
- Add permission checks for non-owner users
- Update workspace invite documentation
Acceptance criteria
- Owner can invite a user by email
- Invited user can accept
- New user can create an account and join
- Non-owner cannot invite
- Revoked invite cannot be used
- Expired invite cannot be used
- Workspace settings UI updated
- Docs updated
Tests
- Unit tests passed
- Integration tests passed
- Permission tests passed
- Email rendering requires staging verification
Files changed
- invitation model
- workspace settings UI
- invite acceptance route
- permission checks
- docs/workspace-invites.md
Risks
Email delivery is mocked locally. Recommend staging email test before merge.
Recommendation