Skip to main content
instantly-enterprise-rbac Configure Instantly.ai workspace access control, team management, and API key governance.
Use when managing workspace members, setting up team permissions,
or implementing API key governance for multi-user Instantly workspaces.
Trigger with phrases like "instantly team", "instantly permissions",
"instantly workspace members", "instantly access control", "instantly rbac".
跳到安装 Skills Marketplace 发现并探索由社区构建的 Agent Skills
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/jeremylongshore/claude-code-plugins-plus-skills --skill instantly-enterprise-rbac命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
下载 Zip 下载中... 同仓库更多 Skills Implement user sign-up and sign-in flows with Clerk.
Use when building authentication UI, customizing sign-in experience,
or implementing OAuth social login.
Trigger with phrases like "clerk sign-in", "clerk sign-up",
"clerk login flow", "clerk OAuth", "clerk social login".
Implement session management and middleware with Clerk.
Use when managing user sessions, configuring route protection,
or implementing token refresh and custom JWT templates.
Trigger with phrases like "clerk session", "clerk middleware",
"clerk route protection", "clerk token", "clerk JWT".
Configure enterprise SSO, role-based access control, and organization management.
Use when implementing SSO integration, configuring role-based permissions,
or setting up organization-level controls.
Trigger with phrases like "clerk SSO", "clerk RBAC",
"clerk enterprise", "clerk roles", "clerk permissions", "clerk organizations".
jeremylongshore
jeremylongshore/claude-code-plugins-plus-skills
打开 GitHub 仓库 name instantly-enterprise-rbac description Configure Instantly.ai workspace access control, team management, and API key governance.
Use when managing workspace members, setting up team permissions,
or implementing API key governance for multi-user Instantly workspaces.
Trigger with phrases like "instantly team", "instantly permissions",
"instantly workspace members", "instantly access control", "instantly rbac".
allowed-tools Read, Write, Edit, Bash(npm:*), Bash(curl:*), Grep version 1.12.0 license MIT author Jeremy Longshore <jeremy@intentsolutions.io> tags ["saas","instantly","enterprise","access-control","team-management"] compatibility Designed for Claude Code, also compatible with Codex and OpenClaw
Instantly Enterprise RBAC
Overview
Manage workspace access control in Instantly API v2. Covers workspace member management, API key governance with scoped permissions, workspace group management (for agencies), custom tag-based resource isolation, and audit logging. Instantly uses workspace-level isolation — each workspace is a separate tenant with its own data and API keys.
Prerequisites
Instantly Hypergrowth plan or higher
Workspace admin access
API key with all:all scope (for admin operations)
Instructions
Step 1: Workspace Member Management
import { InstantlyClient } from "./src/instantly/client" ;
const client = new InstantlyClient ();
async function listMembers ( ) {
const members = await client.request <Array <{
id : string ;
email : string ;
role : string ;
timestamp_created : string ;
}>>("/workspace-members" );
console .log ("Workspace Members:" );
for (const m of members) {
console .log (` ${m.email} — role: ${m.role} (joined: ${m.timestamp_created} )` );
}
return members;
}
( ) {
member = client. <{ : ; : }>( , {
: ,
: . ({ email }),
});
. ( );
member;
}
( ) {
client. ( , {
: ,
: . ({ role }),
});
}
( ) {
client. ( , { : });
. ( );
}
async
function
inviteMember
email : string
const
await
request
id
string
email
string
"/workspace-members"
method
"POST"
body
JSON
stringify
console
log
`Invited: ${member.email} (${member.id} )`
return
async
function
updateMemberRole
memberId : string , role : string
await
request
`/workspace-members/${memberId} `
method
"PATCH"
body
JSON
stringify
async
function
removeMember
memberId : string
await
request
`/workspace-members/${memberId} `
method
"DELETE"
console
log
`Removed member: ${memberId} `
Step 2: API Key Governance
async function createScopedKeys ( ) {
const analyticsKey = await client.request <{ id : string ; key : string ; name : string }>(
"/api-keys" ,
{
method : "POST" ,
body : JSON .stringify ({
name : "Marketing — Analytics Read Only" ,
scopes : ["campaigns:read" , "accounts:read" ],
}),
}
);
console .log (`Analytics key: ${analyticsKey.name} (${analyticsKey.id} )` );
const sdrKey = await client.request <{ id : string ; key : string ; name : string }>(
"/api-keys" ,
{
method : "POST" ,
body : JSON .stringify ({
name : "SDR — Campaign Management" ,
scopes : ["campaigns:all" , "leads:all" ],
}),
}
);
console .log (`SDR key: ${sdrKey.name} (${sdrKey.id} )` );
const webhookKey = await client.request <{ id : string ; key : string ; name : string }>(
"/api-keys" ,
{
method : "POST" ,
body : JSON .stringify ({
name : "Integration Service — Webhook Handler" ,
scopes : ["leads:read" ],
}),
}
);
console .log (`Webhook key: ${webhookKey.name} (${webhookKey.id} )` );
}
async function auditApiKeys ( ) {
const keys = await client.request <Array <{
id : string ; name : string ; scopes : string []; timestamp_created : string ;
}>>("/api-keys" );
console .log ("API Keys:" );
for (const key of keys) {
console .log (` ${key.name} (${key.id} )` );
console .log (` Scopes: ${key.scopes.join(", " )} ` );
console .log (` Created: ${key.timestamp_created} ` );
}
const overprivileged = keys.filter ((k ) =>
k.scopes .includes ("all:all" ) || k.scopes .includes ("all:update" )
);
if (overprivileged.length > 0 ) {
console .log (`\nWARNING: ${overprivileged.length} key(s) with all:all scope:` );
overprivileged.forEach ((k ) => console .log (` ${k.name} — consider reducing scope` ));
}
}
async function revokeApiKey (keyId : string ) {
await client.request (`/api-keys/${keyId} ` , { method : "DELETE" });
console .log (`Revoked API key: ${keyId} ` );
}
Step 3: Workspace Group Management (Agency Pattern)
async function manageWorkspaceGroups ( ) {
const groupMembers = await client.request <Array <{
id : string ; email : string ;
}>>("/workspace-group-members" );
console .log ("Workspace Group Members:" );
for (const m of groupMembers) {
console .log (` ${m.email} (${m.id} )` );
}
await client.request ("/workspace-group-members" , {
method : "POST" ,
body : JSON .stringify ({ email : "team@agency.com" }),
});
const admins = await client.request <Array <{
id : string ; email : string ;
}>>("/workspace-group-members/admin" );
console .log ("Admins:" , admins.map ((a ) => a.email ).join (", " ));
}
Step 4: Custom Tags for Resource Isolation
async function setupTeamTags ( ) {
const teams = ["SDR-West" , "SDR-East" , "Marketing" , "Enterprise" ];
for (const team of teams) {
const tag = await client.request <{ id : string ; label : string }>("/custom-tags" , {
method : "POST" ,
body : JSON .stringify ({
label : team,
description : `Resources owned by ${team} team` ,
}),
});
console .log (`Created tag: ${tag.label} (${tag.id} )` );
}
}
async function tagResource (tagId : string , resourceId : string ) {
await client.request ("/custom-tags/toggle-resource" , {
method : "POST" ,
body : JSON .stringify ({
tag_id : tagId,
resource_id : resourceId,
}),
});
}
async function getCampaignsByTeam (tagId : string ) {
return client.request <Campaign []>(`/campaigns?tag_ids=${tagId} &limit=100` );
}
async function getAccountsByTeam (tagId : string ) {
return client.request <Account []>(`/accounts?tag_ids=${tagId} &limit=100` );
}
Step 5: Audit Logging
async function reviewAuditLogs ( ) {
const logs = await client.request <Array <{
id : string ;
action : string ;
resource : string ;
user : string ;
timestamp_created : string ;
}>>("/audit-logs?limit=50" );
console .log ("Recent Audit Events:" );
for (const log of logs) {
console .log (` ${log.timestamp_created} | ${log.user} | ${log.action} | ${log.resource} ` );
}
return logs;
}
async function changeWorkspaceOwner (newOwnerUserId : string ) {
await client.request ("/workspaces/current/change-owner" , {
method : "POST" ,
body : JSON .stringify ({ new_owner_id : newOwnerUserId }),
});
console .log ("Workspace ownership transferred" );
}
Access Control Matrix Role Campaigns Leads Accounts Webhooks API Keys Members Admin Full Full Full Full Full Full Manager Create/Edit Create/Edit View Create View View SDR Launch/Pause Import View - - - Viewer View only View only View only - - -
Key API Endpoints Method Path Purpose POST/workspace-membersInvite member GET/workspace-membersList members PATCH/workspace-members/{id}Update role DELETE/workspace-members/{id}Remove member POST/api-keysCreate scoped key GET/api-keysList keys DELETE/api-keys/{id}Revoke key POST/custom-tagsCreate tag POST/custom-tags/toggle-resourceTag a resource GET/audit-logsView audit trail POST/workspaces/current/change-ownerTransfer ownership
Error Handling Error Cause Solution 403 on member operationsNot workspace admin Use admin API key Can't revoke own key Self-revocation blocked Use another key or dashboard Tags not filtering Wrong tag_id format Ensure UUID format Audit logs empty Feature not available on plan Upgrade to higher tier
Resources
Next Steps For migration strategies, see instantly-migration-deep-dive.