Skip to main content 首页 创作者 jeremylongshore tons-of-skills-marketplace instantly-enterprise-rbac
instantly-enterprise-rbac Configure Instantly.ai workspace access control, team management, and API key governance.
Use when managing workspace members, setting up team permissions,
or implementing API key governance for multi-user Instantly workspaces.
Trigger with phrases like "instantly team", "instantly permissions",
"instantly workspace members", "instantly access control", "instantly rbac".
跳到安装 Skills Marketplace 发现并探索由社区构建的 Agent Skills
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/jeremylongshore/tons-of-skills-marketplace --skill instantly-enterprise-rbac命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
下载 Zip 下载中... 同仓库更多 Skills langchain-deploy-integration Deploy a LangChain 1.0 / LangGraph 1.0 app to Cloud Run, Vercel, or LangServe correctly — with timeouts sized for chain length, cold-start mitigation, SSE anti-buffering headers, and Secret Manager over .env. Use when prepping a first production deploy, debugging a stream that hangs behind a proxy, or diagnosing p99 latency spikes. Trigger with "langchain deploy", "langchain cloud run", "langchain vercel python", "langchain langserve", or "langchain docker".
langchain-langgraph-agents Build a correct LangGraph 1.0 ReAct agent with create_react_agent — typed tools, error propagation, recursion caps, and stop conditions that actually stop. Use when writing a first tool-calling agent, migrating from AgentExecutor or initialize_agent, or diagnosing an agent that loops on vague prompts. Trigger with "langgraph agent", "create_react_agent", "langgraph tool calling", "AgentExecutor migration", or "agent loop cost".
langchain-langgraph-human-in-loop Build LangGraph 1.0 human-in-the-loop approval flows with interrupt_before /
interrupt_after and Command(resume=...) — JSON-serializable state, clean
resume semantics, and UI wiring for approval decisions. Use when adding an
approval gate before an expensive tool call, wiring a Slack/web UI for agent
approvals, or debugging a graph that crashes on interrupt.
Trigger with "langgraph human in loop", "langgraph interrupt_before",
"langgraph approval flow", "Command resume", "langgraph HITL".
name instantly-enterprise-rbac description Configure Instantly.ai workspace access control, team management, and API key governance.
Use when managing workspace members, setting up team permissions,
or implementing API key governance for multi-user Instantly workspaces.
Trigger with phrases like "instantly team", "instantly permissions",
"instantly workspace members", "instantly access control", "instantly rbac".
allowed-tools Read, Write, Edit, Bash(npm:*), Bash(curl:*), Grep version 1.12.0 license MIT author Jeremy Longshore <jeremy@intentsolutions.io> tags ["saas","instantly","enterprise","access-control","team-management"] compatibility Designed for Claude Code
Instantly Enterprise RBAC
Overview
Manage workspace access control in Instantly API v2. Covers workspace member management, API key governance with scoped permissions, workspace group management (for agencies), custom tag-based resource isolation, and audit logging. Instantly uses workspace-level isolation — each workspace is a separate tenant with its own data and API keys.
Prerequisites
Instantly Hypergrowth plan or higher
Workspace admin access
API key with all:all scope (for admin operations)
Instructions
Step 1: Workspace Member Management
import { InstantlyClient } from "./src/instantly/client" ;
const client = new InstantlyClient ();
async function listMembers ( ) {
const members = await client.request <Array <{
id : string ;
email : string ;
role : string ;
timestamp_created : string ;
}>>("/workspace-members" );
console .log ("Workspace Members:" );
for (const m of members) {
console .log (` ${m.email} — role: ${m.role} (joined: ${m.timestamp_created} )` );
}
return members;
}
( ) {
member = client. <{ : ; : }>( , {
: ,
: . ({ email }),
});
. ( );
member;
}
( ) {
client. ( , {
: ,
: . ({ role }),
});
}
( ) {
client. ( , { : });
. ( );
}
async
function
inviteMember
email : string
const
await
request
id
string
email
string
"/workspace-members"
method
"POST"
body
JSON
stringify
console
log
`Invited: ${member.email} (${member.id} )`
return
async
function
updateMemberRole
memberId : string , role : string
await
request
`/workspace-members/${memberId} `
method
"PATCH"
body
JSON
stringify
async
function
removeMember
memberId : string
await
request
`/workspace-members/${memberId} `
method
"DELETE"
console
log
`Removed member: ${memberId} `
Step 2: API Key Governance
async function createScopedKeys ( ) {
const analyticsKey = await client.request <{ id : string ; key : string ; name : string }>(
"/api-keys" ,
{
method : "POST" ,
body : JSON .stringify ({
name : "Marketing — Analytics Read Only" ,
scopes : ["campaigns:read" , "accounts:read" ],
}),
}
);
console .log (`Analytics key: ${analyticsKey.name} (${analyticsKey.id} )` );
const sdrKey = await client.request <{ id : string ; key : string ; name : string }>(
"/api-keys" ,
{
method : "POST" ,
body : JSON .stringify ({
name : "SDR — Campaign Management" ,
scopes : ["campaigns:all" , "leads:all" ],
}),
}
);
console .log (`SDR key: ${sdrKey.name} (${sdrKey.id} )` );
const webhookKey = await client.request <{ id : string ; key : string ; name : string }>(
"/api-keys" ,
{
method : "POST" ,
body : JSON .stringify ({
name : "Integration Service — Webhook Handler" ,
scopes : ["leads:read" ],
}),
}
);
console .log (`Webhook key: ${webhookKey.name} (${webhookKey.id} )` );
}
async function auditApiKeys ( ) {
const keys = await client.request <Array <{
id : string ; name : string ; scopes : string []; timestamp_created : string ;
}>>("/api-keys" );
console .log ("API Keys:" );
for (const key of keys) {
console .log (` ${key.name} (${key.id} )` );
console .log (` Scopes: ${key.scopes.join(", " )} ` );
console .log (` Created: ${key.timestamp_created} ` );
}
const overprivileged = keys.filter ((k ) =>
k.scopes .includes ("all:all" ) || k.scopes .includes ("all:update" )
);
if (overprivileged.length > 0 ) {
console .log (`\nWARNING: ${overprivileged.length} key(s) with all:all scope:` );
overprivileged.forEach ((k ) => console .log (` ${k.name} — consider reducing scope` ));
}
}
async function revokeApiKey (keyId : string ) {
await client.request (`/api-keys/${keyId} ` , { method : "DELETE" });
console .log (`Revoked API key: ${keyId} ` );
}
Step 3: Workspace Group Management (Agency Pattern)
async function manageWorkspaceGroups ( ) {
const groupMembers = await client.request <Array <{
id : string ; email : string ;
}>>("/workspace-group-members" );
console .log ("Workspace Group Members:" );
for (const m of groupMembers) {
console .log (` ${m.email} (${m.id} )` );
}
await client.request ("/workspace-group-members" , {
method : "POST" ,
body : JSON .stringify ({ email : "team@agency.com" }),
});
const admins = await client.request <Array <{
id : string ; email : string ;
}>>("/workspace-group-members/admin" );
console .log ("Admins:" , admins.map ((a ) => a.email ).join (", " ));
}
Step 4: Custom Tags for Resource Isolation
async function setupTeamTags ( ) {
const teams = ["SDR-West" , "SDR-East" , "Marketing" , "Enterprise" ];
for (const team of teams) {
const tag = await client.request <{ id : string ; label : string }>("/custom-tags" , {
method : "POST" ,
body : JSON .stringify ({
label : team,
description : `Resources owned by ${team} team` ,
}),
});
console .log (`Created tag: ${tag.label} (${tag.id} )` );
}
}
async function tagResource (tagId : string , resourceId : string ) {
await client.request ("/custom-tags/toggle-resource" , {
method : "POST" ,
body : JSON .stringify ({
tag_id : tagId,
resource_id : resourceId,
}),
});
}
async function getCampaignsByTeam (tagId : string ) {
return client.request <Campaign []>(`/campaigns?tag_ids=${tagId} &limit=100` );
}
async function getAccountsByTeam (tagId : string ) {
return client.request <Account []>(`/accounts?tag_ids=${tagId} &limit=100` );
}
Step 5: Audit Logging
async function reviewAuditLogs ( ) {
const logs = await client.request <Array <{
id : string ;
action : string ;
resource : string ;
user : string ;
timestamp_created : string ;
}>>("/audit-logs?limit=50" );
console .log ("Recent Audit Events:" );
for (const log of logs) {
console .log (` ${log.timestamp_created} | ${log.user} | ${log.action} | ${log.resource} ` );
}
return logs;
}
async function changeWorkspaceOwner (newOwnerUserId : string ) {
await client.request ("/workspaces/current/change-owner" , {
method : "POST" ,
body : JSON .stringify ({ new_owner_id : newOwnerUserId }),
});
console .log ("Workspace ownership transferred" );
}
Access Control Matrix Role Campaigns Leads Accounts Webhooks API Keys Members Admin Full Full Full Full Full Full Manager Create/Edit Create/Edit View Create View View SDR Launch/Pause Import View - - - Viewer View only View only View only - - -
Key API Endpoints Method Path Purpose POST/workspace-membersInvite member GET/workspace-membersList members PATCH/workspace-members/{id}Update role DELETE/workspace-members/{id}Remove member POST/api-keysCreate scoped key GET/api-keysList keys DELETE/api-keys/{id}Revoke key POST/custom-tagsCreate tag POST/custom-tags/toggle-resourceTag a resource GET/audit-logsView audit trail POST/workspaces/current/change-ownerTransfer ownership
Error Handling Error Cause Solution 403 on member operationsNot workspace admin Use admin API key Can't revoke own key Self-revocation blocked Use another key or dashboard Tags not filtering Wrong tag_id format Ensure UUID format Audit logs empty Feature not available on plan Upgrade to higher tier
Resources
Next Steps For migration strategies, see instantly-migration-deep-dive.