boxd auth org and boxd teams on the CLI, and from the SDKs’ orgs and teams namespaces.
Roles
Create an org and manage its roster
- Invites carry a role. The invitee lands as
memberoradmin, and an admin invite can only be sent from an interactive login. An API key or a token minted inside a machine cannot send one, and cannot read the links of pending invites either. It still sees that an invite is pending. - Demoting another admin is owner-only. An admin can always demote themselves.
- The owner’s role cannot be changed with
set-role, and an owner or admin cannot be removed withremove-member. Both go through the boxd team. - A member who still owns org-billed machines cannot be removed. Move those machines to personal billing or destroy them first.
boxd auth switch acme first, or pass --org acme for one call.