Organizations
Teams with their own roles and permissions, layered under the platform's global ones.
The problem
Sooner or later two people want to share an account. Bolting that on after launch means rewriting every query that assumed one user owns everything.
What Bones does
Organizations are built in from the start.
- Scoped roles. Each organization has its own roles and its own feature × role grid, separate from the platform's global roles.
- Two layers of switches. An organization feature only works when the platform-wide flag is also on. Turn a feature off globally and every organization loses it, while each organization's own setting is kept for when it comes back.
- Safe membership. Removing a member is a soft delete, and the last admin of an organization can't be removed.
- A default organization. A fresh database has one, and the first user joins it as admin.
- Per-organization features. The chatbot on the home page is an organization feature, so each organization decides which of its roles can use it.
How it compares
Rolling your own usually starts with an org_id column and grows into a permission system by accident. Bones ships the permission system first, so organizations reuse it.
Go deeper
- Roles and permissions — the global model organizations build on.
- Checking permissions —
requireOrganizationPermission.