wf-team-invite
Purpose
Turns a pasted list of people — "name + address", in whatever shape a human
wrote it — into user accounts, roles, staff cards and invitations, and sends
each person the link that signs them in.
It exists because four services have to move together for one row of that list
(, rp-identity, rp-access, rp-staff plus a mail lambda) andrp-auth
microservices do not call each other.
Why it is also the privilege boundary
refuses a user JWT outright (rp-access), so no surface@Access("internal")
can hand out a role. centimanus runs this script with , and whoSERVICE_TOKEN
may run it is an ordinary grant — — checkedwf/workflows/wf-team-invite.js(x)
at the edge () and written in one preset file. That issignal_provider.zig:146
why the product has no "administrator" concept.
The script cannot see who called it, so the escalation guard is a fixed list:, manager, operator. viewer and owner are not grantable here.root
Shape
- text sources —
+files.materialize, plusfiles.extractText;rawText - people —
first, a line-by-line regex as the fallback;rt.llm - one
per person — user, base preset + role, group tags, card,rt.attempt
invitation; - the letter — its own attempt, so a refused relay is a branch and not a lost
account; - the report, whose
the surface turns into an open table of exactlystaffIds
these people.
Re-running the same list is harmless: a known address is , never aupdated
second account.
Direct module dependencies
,g-access,g-auth,g-files,g-identity,g-notify,g-ses,g-smtpg-staff
Solution membership
production
Source
modules/workflows/wf-team-invite