Teams and invitations
Firm owners and authorized staff use the Teams area to review members and invite people into the firm. Invitations connect an email address to a firm membership; they do not create a different identity model.
Status: Member and invitation flows are implemented. Invitation email delivery depends on the deployment’s email configuration.
Invite lifecycle
- An authorized member submits an invitee’s email and firm role.
- The API records the invitation and sends the invitation email through the configured email service.
- The recipient opens the invitation link. The UI verifies the invitation and displays the invited email and firm.
- The recipient creates an account or signs in with the matching email. The API accepts the invitation and creates the firm membership.
- Later requests are authorized through that membership and the role required by each API operation.
An invitation is only useful while the relevant API and email delivery configuration are available. Email provider setup and deliverability are deployment concerns.
Membership and roles
Users can belong to firms through separate membership records. The UI may show controls based on a role, but the API enforces permission checks when member and invitation changes are requested. The Identity and firm access guide explains the authorization model.
Related guides
- Account and password recovery explains the recipient sign-in and signup paths.
- Profile and firm settings covers user profile and firm branding changes.
Code map
- UI team management and invite handoff: WhizBoard UI,
src/routes/$firmSlug.teams.tsx,src/lib/team-management.ts, andsrc/lib/invite-login.ts. - API invitation and membership logic: backend,
src/routers/invitations.py,src/services/invitations.py, andsrc/models/membership.py.
