Organization model
Last updated:
An organization is the Helium-owned governance boundary for memberships, framework roles, active context, billing authority, and other organization-scoped framework capabilities.
Model
- An organization has a stable
OrganizationId, a mutable name, an opaque version token, and the Initial MVP stateactive. - A membership links one account to one organization and carries one semantic framework role.
- An invitation is a single-use, email-bound offer to create a membership. It is not itself membership authority.
- Ownership is represented by one or more current memberships with role
Owner; there is no separate primary-owner field. - The active-organization preference is navigation state only. It must be revalidated before protected use.
Use organization for framework contracts and persisted state. Use tenant only when describing the security-isolation property of organization-scoped data.
Invariants
- Every organization has at least one current Owner.
- One account has at most one current membership in an organization.
- Removed membership history grants no context or authority.
- Role authority comes from current framework state, not claims, routes, headers, or cookies.
- Organization-owned reads and mutations require explicit authoritative organization scope.
- General creation of additional organizations after onboarding is not part of the Initial MVP public API.
Current implementation status
Organization persistence, first-organization creation, membership discovery, organization retrieval, and organization-name updates are implemented preview foundations. Invitation administration, general member administration, active context, authorization, ownership transfer, and complete isolation verification remain in WS-005.