Skip to main content
instantly-enterprise-rbac Configure Instantly.ai workspace access control, team management, and API key governance.
Use when managing workspace members, setting up team permissions,
or implementing API key governance for multi-user Instantly workspaces.
Trigger with phrases like "instantly team", "instantly permissions",
"instantly workspace members", "instantly access control", "instantly rbac".
Aller à l'installation Skills Marketplace Découvrez et explorez les compétences IA créées par la communauté.
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Copier le promptAfficher les détails du prompt Une commande directe contourne le prompt de vérification. Examinez la source avant de l'exécuter.
npx skills add https://github.com/jeremylongshore/claude-code-plugins-plus-skills --skill instantly-enterprise-rbacLa commande reste sur une seule ligne. Faites défiler horizontalement pour la vérifier avant de la copier.
Vous préférez une copie locale ? Téléchargez les fichiers actuellement disponibles dans SkillsMP.
Télécharger Zip Téléchargement... Plus depuis ce dépôt Implement user sign-up and sign-in flows with Clerk.
Use when building authentication UI, customizing sign-in experience,
or implementing OAuth social login.
Trigger with phrases like "clerk sign-in", "clerk sign-up",
"clerk login flow", "clerk OAuth", "clerk social login".
Implement session management and middleware with Clerk.
Use when managing user sessions, configuring route protection,
or implementing token refresh and custom JWT templates.
Trigger with phrases like "clerk session", "clerk middleware",
"clerk route protection", "clerk token", "clerk JWT".
Configure enterprise SSO, role-based access control, and organization management.
Use when implementing SSO integration, configuring role-based permissions,
or setting up organization-level controls.
Trigger with phrases like "clerk SSO", "clerk RBAC",
"clerk enterprise", "clerk roles", "clerk permissions", "clerk organizations".
Métiers associés SOC
Basé sur la classification professionnelle SOC
name instantly-enterprise-rbac description Configure Instantly.ai workspace access control, team management, and API key governance.
Use when managing workspace members, setting up team permissions,
or implementing API key governance for multi-user Instantly workspaces.
Trigger with phrases like "instantly team", "instantly permissions",
"instantly workspace members", "instantly access control", "instantly rbac".
allowed-tools Read, Write, Edit, Bash(npm:*), Bash(curl:*), Grep version 1.12.0 license MIT author Jeremy Longshore <jeremy@intentsolutions.io> tags ["saas","instantly","enterprise","access-control","team-management"] compatibility Designed for Claude Code, also compatible with Codex and OpenClaw
Instantly Enterprise RBAC
Overview
Manage workspace access control in Instantly API v2. Covers workspace member management, API key governance with scoped permissions, workspace group management (for agencies), custom tag-based resource isolation, and audit logging. Instantly uses workspace-level isolation — each workspace is a separate tenant with its own data and API keys.
Prerequisites
Instantly Hypergrowth plan or higher
Workspace admin access
API key with all:all scope (for admin operations)
Instructions
Step 1: Workspace Member Management
import { InstantlyClient } from "./src/instantly/client" ;
const client = new InstantlyClient ();
async function listMembers ( ) {
const members = await client.request <Array <{
id : string ;
email : string ;
role : string ;
timestamp_created : string ;
}>>("/workspace-members" );
console .log ("Workspace Members:" );
for (const m of members) {
console .log (` ${m.email} — role: ${m.role} (joined: ${m.timestamp_created} )` );
}
return members;
}
( ) {
member = client. <{ : ; : }>( , {
: ,
: . ({ email }),
});
. ( );
member;
}
( ) {
client. ( , {
: ,
: . ({ role }),
});
}
( ) {
client. ( , { : });
. ( );
}
async
function
inviteMember
email : string
const
await
request
id
string
email
string
"/workspace-members"
method
"POST"
body
JSON
stringify
console
log
`Invited: ${member.email} (${member.id} )`
return
async
function
updateMemberRole
memberId : string , role : string
await
request
`/workspace-members/${memberId} `
method
"PATCH"
body
JSON
stringify
async
function
removeMember
memberId : string
await
request
`/workspace-members/${memberId} `
method
"DELETE"
console
log
`Removed member: ${memberId} `
Step 2: API Key Governance
async function createScopedKeys ( ) {
const analyticsKey = await client.request <{ id : string ; key : string ; name : string }>(
"/api-keys" ,
{
method : "POST" ,
body : JSON .stringify ({
name : "Marketing — Analytics Read Only" ,
scopes : ["campaigns:read" , "accounts:read" ],
}),
}
);
console .log (`Analytics key: ${analyticsKey.name} (${analyticsKey.id} )` );
const sdrKey = await client.request <{ id : string ; key : string ; name : string }>(
"/api-keys" ,
{
method : "POST" ,
body : JSON .stringify ({
name : "SDR — Campaign Management" ,
scopes : ["campaigns:all" , "leads:all" ],
}),
}
);
console .log (`SDR key: ${sdrKey.name} (${sdrKey.id} )` );
const webhookKey = await client.request <{ id : string ; key : string ; name : string }>(
"/api-keys" ,
{
method : "POST" ,
body : JSON .stringify ({
name : "Integration Service — Webhook Handler" ,
scopes : ["leads:read" ],
}),
}
);
console .log (`Webhook key: ${webhookKey.name} (${webhookKey.id} )` );
}
async function auditApiKeys ( ) {
const keys = await client.request <Array <{
id : string ; name : string ; scopes : string []; timestamp_created : string ;
}>>("/api-keys" );
console .log ("API Keys:" );
for (const key of keys) {
console .log (` ${key.name} (${key.id} )` );
console .log (` Scopes: ${key.scopes.join(", " )} ` );
console .log (` Created: ${key.timestamp_created} ` );
}
const overprivileged = keys.filter ((k ) =>
k.scopes .includes ("all:all" ) || k.scopes .includes ("all:update" )
);
if (overprivileged.length > 0 ) {
console .log (`\nWARNING: ${overprivileged.length} key(s) with all:all scope:` );
overprivileged.forEach ((k ) => console .log (` ${k.name} — consider reducing scope` ));
}
}
async function revokeApiKey (keyId : string ) {
await client.request (`/api-keys/${keyId} ` , { method : "DELETE" });
console .log (`Revoked API key: ${keyId} ` );
}
Step 3: Workspace Group Management (Agency Pattern)
async function manageWorkspaceGroups ( ) {
const groupMembers = await client.request <Array <{
id : string ; email : string ;
}>>("/workspace-group-members" );
console .log ("Workspace Group Members:" );
for (const m of groupMembers) {
console .log (` ${m.email} (${m.id} )` );
}
await client.request ("/workspace-group-members" , {
method : "POST" ,
body : JSON .stringify ({ email : "team@agency.com" }),
});
const admins = await client.request <Array <{
id : string ; email : string ;
}>>("/workspace-group-members/admin" );
console .log ("Admins:" , admins.map ((a ) => a.email ).join (", " ));
}
Step 4: Custom Tags for Resource Isolation
async function setupTeamTags ( ) {
const teams = ["SDR-West" , "SDR-East" , "Marketing" , "Enterprise" ];
for (const team of teams) {
const tag = await client.request <{ id : string ; label : string }>("/custom-tags" , {
method : "POST" ,
body : JSON .stringify ({
label : team,
description : `Resources owned by ${team} team` ,
}),
});
console .log (`Created tag: ${tag.label} (${tag.id} )` );
}
}
async function tagResource (tagId : string , resourceId : string ) {
await client.request ("/custom-tags/toggle-resource" , {
method : "POST" ,
body : JSON .stringify ({
tag_id : tagId,
resource_id : resourceId,
}),
});
}
async function getCampaignsByTeam (tagId : string ) {
return client.request <Campaign []>(`/campaigns?tag_ids=${tagId} &limit=100` );
}
async function getAccountsByTeam (tagId : string ) {
return client.request <Account []>(`/accounts?tag_ids=${tagId} &limit=100` );
}
Step 5: Audit Logging
async function reviewAuditLogs ( ) {
const logs = await client.request <Array <{
id : string ;
action : string ;
resource : string ;
user : string ;
timestamp_created : string ;
}>>("/audit-logs?limit=50" );
console .log ("Recent Audit Events:" );
for (const log of logs) {
console .log (` ${log.timestamp_created} | ${log.user} | ${log.action} | ${log.resource} ` );
}
return logs;
}
async function changeWorkspaceOwner (newOwnerUserId : string ) {
await client.request ("/workspaces/current/change-owner" , {
method : "POST" ,
body : JSON .stringify ({ new_owner_id : newOwnerUserId }),
});
console .log ("Workspace ownership transferred" );
}
Access Control Matrix Role Campaigns Leads Accounts Webhooks API Keys Members Admin Full Full Full Full Full Full Manager Create/Edit Create/Edit View Create View View SDR Launch/Pause Import View - - - Viewer View only View only View only - - -
Key API Endpoints Method Path Purpose POST/workspace-membersInvite member GET/workspace-membersList members PATCH/workspace-members/{id}Update role DELETE/workspace-members/{id}Remove member POST/api-keysCreate scoped key GET/api-keysList keys DELETE/api-keys/{id}Revoke key POST/custom-tagsCreate tag POST/custom-tags/toggle-resourceTag a resource GET/audit-logsView audit trail POST/workspaces/current/change-ownerTransfer ownership
Error Handling Error Cause Solution 403 on member operationsNot workspace admin Use admin API key Can't revoke own key Self-revocation blocked Use another key or dashboard Tags not filtering Wrong tag_id format Ensure UUID format Audit logs empty Feature not available on plan Upgrade to higher tier
Resources
Next Steps For migration strategies, see instantly-migration-deep-dive.