Skip to main content
instantly-enterprise-rbac Configure Instantly.ai workspace access control, team management, and API key governance.
Use when managing workspace members, setting up team permissions,
or implementing API key governance for multi-user Instantly workspaces.
Trigger with phrases like "instantly team", "instantly permissions",
"instantly workspace members", "instantly access control", "instantly rbac".
インストールへ移動 Skills Marketplace コミュニティが作成したAIスキルを発見・探索
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
直接コマンドでは確認用 Prompt が省略されます。実行前にソースを確認してください。
npx skills add https://github.com/jeremylongshore/claude-code-plugins-plus-skills --skill instantly-enterprise-rbacコマンドは1行のまま表示されます。コピー前に横へスクロールして全体を確認してください。
ローカルで確認しますか?SkillsMP が現在取得できるファイルをダウンロードできます。
Zipをダウンロード ダウンロード中... このリポジトリの他の Skills Implement user sign-up and sign-in flows with Clerk.
Use when building authentication UI, customizing sign-in experience,
or implementing OAuth social login.
Trigger with phrases like "clerk sign-in", "clerk sign-up",
"clerk login flow", "clerk OAuth", "clerk social login".
Implement session management and middleware with Clerk.
Use when managing user sessions, configuring route protection,
or implementing token refresh and custom JWT templates.
Trigger with phrases like "clerk session", "clerk middleware",
"clerk route protection", "clerk token", "clerk JWT".
Configure enterprise SSO, role-based access control, and organization management.
Use when implementing SSO integration, configuring role-based permissions,
or setting up organization-level controls.
Trigger with phrases like "clerk SSO", "clerk RBAC",
"clerk enterprise", "clerk roles", "clerk permissions", "clerk organizations".
name instantly-enterprise-rbac description Configure Instantly.ai workspace access control, team management, and API key governance.
Use when managing workspace members, setting up team permissions,
or implementing API key governance for multi-user Instantly workspaces.
Trigger with phrases like "instantly team", "instantly permissions",
"instantly workspace members", "instantly access control", "instantly rbac".
allowed-tools Read, Write, Edit, Bash(npm:*), Bash(curl:*), Grep version 1.12.0 license MIT author Jeremy Longshore <jeremy@intentsolutions.io> tags ["saas","instantly","enterprise","access-control","team-management"] compatibility Designed for Claude Code, also compatible with Codex and OpenClaw
Instantly Enterprise RBAC
Overview
Manage workspace access control in Instantly API v2. Covers workspace member management, API key governance with scoped permissions, workspace group management (for agencies), custom tag-based resource isolation, and audit logging. Instantly uses workspace-level isolation — each workspace is a separate tenant with its own data and API keys.
Prerequisites
Instantly Hypergrowth plan or higher
Workspace admin access
API key with all:all scope (for admin operations)
Instructions
Step 1: Workspace Member Management
import { InstantlyClient } from "./src/instantly/client" ;
const client = new InstantlyClient ();
async function listMembers ( ) {
const members = await client.request <Array <{
id : string ;
email : string ;
role : string ;
timestamp_created : string ;
}>>("/workspace-members" );
console .log ("Workspace Members:" );
for (const m of members) {
console .log (` ${m.email} — role: ${m.role} (joined: ${m.timestamp_created} )` );
}
return members;
}
( ) {
member = client. <{ : ; : }>( , {
: ,
: . ({ email }),
});
. ( );
member;
}
( ) {
client. ( , {
: ,
: . ({ role }),
});
}
( ) {
client. ( , { : });
. ( );
}
async
function
inviteMember
email : string
const
await
request
id
string
email
string
"/workspace-members"
method
"POST"
body
JSON
stringify
console
log
`Invited: ${member.email} (${member.id} )`
return
async
function
updateMemberRole
memberId : string , role : string
await
request
`/workspace-members/${memberId} `
method
"PATCH"
body
JSON
stringify
async
function
removeMember
memberId : string
await
request
`/workspace-members/${memberId} `
method
"DELETE"
console
log
`Removed member: ${memberId} `
Step 2: API Key Governance
async function createScopedKeys ( ) {
const analyticsKey = await client.request <{ id : string ; key : string ; name : string }>(
"/api-keys" ,
{
method : "POST" ,
body : JSON .stringify ({
name : "Marketing — Analytics Read Only" ,
scopes : ["campaigns:read" , "accounts:read" ],
}),
}
);
console .log (`Analytics key: ${analyticsKey.name} (${analyticsKey.id} )` );
const sdrKey = await client.request <{ id : string ; key : string ; name : string }>(
"/api-keys" ,
{
method : "POST" ,
body : JSON .stringify ({
name : "SDR — Campaign Management" ,
scopes : ["campaigns:all" , "leads:all" ],
}),
}
);
console .log (`SDR key: ${sdrKey.name} (${sdrKey.id} )` );
const webhookKey = await client.request <{ id : string ; key : string ; name : string }>(
"/api-keys" ,
{
method : "POST" ,
body : JSON .stringify ({
name : "Integration Service — Webhook Handler" ,
scopes : ["leads:read" ],
}),
}
);
console .log (`Webhook key: ${webhookKey.name} (${webhookKey.id} )` );
}
async function auditApiKeys ( ) {
const keys = await client.request <Array <{
id : string ; name : string ; scopes : string []; timestamp_created : string ;
}>>("/api-keys" );
console .log ("API Keys:" );
for (const key of keys) {
console .log (` ${key.name} (${key.id} )` );
console .log (` Scopes: ${key.scopes.join(", " )} ` );
console .log (` Created: ${key.timestamp_created} ` );
}
const overprivileged = keys.filter ((k ) =>
k.scopes .includes ("all:all" ) || k.scopes .includes ("all:update" )
);
if (overprivileged.length > 0 ) {
console .log (`\nWARNING: ${overprivileged.length} key(s) with all:all scope:` );
overprivileged.forEach ((k ) => console .log (` ${k.name} — consider reducing scope` ));
}
}
async function revokeApiKey (keyId : string ) {
await client.request (`/api-keys/${keyId} ` , { method : "DELETE" });
console .log (`Revoked API key: ${keyId} ` );
}
Step 3: Workspace Group Management (Agency Pattern)
async function manageWorkspaceGroups ( ) {
const groupMembers = await client.request <Array <{
id : string ; email : string ;
}>>("/workspace-group-members" );
console .log ("Workspace Group Members:" );
for (const m of groupMembers) {
console .log (` ${m.email} (${m.id} )` );
}
await client.request ("/workspace-group-members" , {
method : "POST" ,
body : JSON .stringify ({ email : "team@agency.com" }),
});
const admins = await client.request <Array <{
id : string ; email : string ;
}>>("/workspace-group-members/admin" );
console .log ("Admins:" , admins.map ((a ) => a.email ).join (", " ));
}
Step 4: Custom Tags for Resource Isolation
async function setupTeamTags ( ) {
const teams = ["SDR-West" , "SDR-East" , "Marketing" , "Enterprise" ];
for (const team of teams) {
const tag = await client.request <{ id : string ; label : string }>("/custom-tags" , {
method : "POST" ,
body : JSON .stringify ({
label : team,
description : `Resources owned by ${team} team` ,
}),
});
console .log (`Created tag: ${tag.label} (${tag.id} )` );
}
}
async function tagResource (tagId : string , resourceId : string ) {
await client.request ("/custom-tags/toggle-resource" , {
method : "POST" ,
body : JSON .stringify ({
tag_id : tagId,
resource_id : resourceId,
}),
});
}
async function getCampaignsByTeam (tagId : string ) {
return client.request <Campaign []>(`/campaigns?tag_ids=${tagId} &limit=100` );
}
async function getAccountsByTeam (tagId : string ) {
return client.request <Account []>(`/accounts?tag_ids=${tagId} &limit=100` );
}
Step 5: Audit Logging
async function reviewAuditLogs ( ) {
const logs = await client.request <Array <{
id : string ;
action : string ;
resource : string ;
user : string ;
timestamp_created : string ;
}>>("/audit-logs?limit=50" );
console .log ("Recent Audit Events:" );
for (const log of logs) {
console .log (` ${log.timestamp_created} | ${log.user} | ${log.action} | ${log.resource} ` );
}
return logs;
}
async function changeWorkspaceOwner (newOwnerUserId : string ) {
await client.request ("/workspaces/current/change-owner" , {
method : "POST" ,
body : JSON .stringify ({ new_owner_id : newOwnerUserId }),
});
console .log ("Workspace ownership transferred" );
}
Access Control Matrix Role Campaigns Leads Accounts Webhooks API Keys Members Admin Full Full Full Full Full Full Manager Create/Edit Create/Edit View Create View View SDR Launch/Pause Import View - - - Viewer View only View only View only - - -
Key API Endpoints Method Path Purpose POST/workspace-membersInvite member GET/workspace-membersList members PATCH/workspace-members/{id}Update role DELETE/workspace-members/{id}Remove member POST/api-keysCreate scoped key GET/api-keysList keys DELETE/api-keys/{id}Revoke key POST/custom-tagsCreate tag POST/custom-tags/toggle-resourceTag a resource GET/audit-logsView audit trail POST/workspaces/current/change-ownerTransfer ownership
Error Handling Error Cause Solution 403 on member operationsNot workspace admin Use admin API key Can't revoke own key Self-revocation blocked Use another key or dashboard Tags not filtering Wrong tag_id format Ensure UUID format Audit logs empty Feature not available on plan Upgrade to higher tier
Resources
Next Steps For migration strategies, see instantly-migration-deep-dive.