Parent epics
#63, #64
User problem
Cloud workspaces need collaboration without making every member an owner. Roles must control campaigns, assets, provider/connector settings, invitations, approvals, exports, and publishing consistently across web, API, jobs, extension, and MCP.
Scope
- Roles: owner, admin, editor, reviewer, and viewer, with a documented permission matrix.
- Invite by email or supported identity, pending/accepted/expired/revoked states, resend, and duplicate handling.
- Member list, role change, removal, transfer ownership, leave workspace, and last-owner safeguards.
- Server-side authorization service/policies consumed by repositories and application commands.
- Permission-aware navigation/actions with explicit read-only and unavailable reasons.
- Extension workspace targeting and MCP access reflect current membership.
- Audit events for invitation, acceptance, role changes, removals, and ownership transfer.
Acceptance criteria
Tests
Full role matrix, invite expiry/reuse, duplicate invite, removed member with open tab, extension pairing after removal, MCP authorization, ownership transfer, last-owner, archived workspace, and cross-tenant ID tampering.
Parent epics
#63, #64
User problem
Cloud workspaces need collaboration without making every member an owner. Roles must control campaigns, assets, provider/connector settings, invitations, approvals, exports, and publishing consistently across web, API, jobs, extension, and MCP.
Scope
Acceptance criteria
Tests
Full role matrix, invite expiry/reuse, duplicate invite, removed member with open tab, extension pairing after removal, MCP authorization, ownership transfer, last-owner, archived workspace, and cross-tenant ID tampering.