Belonging to an organization: invitations, acceptance, and what they change¶
Audience: administrators who bring people into an organization, and anyone who has just received an invitation and wants to know what accepting actually does.
⟨draft — the whole topic awaits the red pen; written the night the feature landed⟩
The idea in one paragraph¶
A person exists once in LQMS, but belongs to organizations one membership at a time — and a membership begins only when the person accepts an invitation. Being invited shows you nothing and grants you nothing; being a member makes you staffable and lists you in that organization's user administration; only roles ever grant access to content. Every step is recorded in the organization's own activity trail: who invited whom, what was offered, what was answered.
Inviting someone¶
From Admin › Users, an administrator of an organization can invite:
- a person already known to this installation — the invitation appears in that person's inbox (scene:admin-users);
- anyone, by email address — the invitation travels as an email carrying a single-use link. If the address has no login here yet, accepting creates one (you set your password through the login system itself — LQMS never sees it). The pending invitation, its expiry and the resend and revoke controls sit on the same page.
An invitation can carry named responsibilities — for example "VAL-CARDIO: Document Author". They are applied the moment the invitation is accepted, and the acceptance acknowledges them by name: the record shows what was offered and what was taken on. ⟨draft: confirm we want to teach pre-assignment in the first paragraph or as an "advanced" note⟩
Accepting — or declining¶
Your open invitations lead your Inbox (scene:inbox). The offer names the organization, the person who invited you, and any responsibilities in words. Accepting makes you a member and applies the offered staffing; declining is final, needs no reason, and grants nothing. If an offered responsibility can no longer be applied (its role was deactivated meanwhile), the membership still completes and the gap is shown to the administrator — nothing fails silently.
What membership does NOT do¶
Membership alone shows you no documents. LQMS separates belonging (you can be staffed, you appear in the roster) from reach (what your roles let you read and do) — so a brand-new member sees an empty document list until someone staffs them, and a person who was never invited sees nothing at all, not even that the organization exists. ⟨draft: this paragraph is the ADR-0108 §1 boundary — keep it prominent, auditors read this page⟩
Leaving, removal, and the difference from deactivation¶
An administrator can end a membership: it unassigns every role the person held in that organization and closes the membership — the person and their history remain. Only an installation operator can deactivate a person (their login everywhere). One organization can never switch off a person who also works elsewhere.
Where the records live¶
MEMBER_INVITED, MEMBER_ACCEPTED, MEMBER_DECLINED and MEMBER_REMOVED are written to the
organization's own trail; applied responsibilities appear as the ordinary staffing events, marked
"membership acceptance", attributed to the inviter whose authority they exercised.