What are Members?
Members are users who belong to a partner organization in the Hyperion platform. Each member has specific permissions (scopes) that determine what actions they can perform within the organization.
The member system enables:
- Team collaboration: Multiple users can work within the same partner organization
- Granular permissions: Assign specific capabilities to each team member
- Access control: Limit sensitive operations to authorized personnel
Members vs Users
It's important to understand the distinction between users and members:
| Concept | Description |
|---|---|
| User | An individual account in the Hyperion platform |
| Member | A user's association with a specific partner organization, including their permissions |
A single user can be a member of multiple partner organizations, with different permissions in each. When a user logs in and selects a partner organization, they operate with the scopes assigned to their membership in that organization.
How are members structured?
{
"id": "550e8400-e29b-41d4-a716-446655440000",
"user": {
"id": "auth0|64f2a1b9e5c321001dfa45bc",
"email": "john.doe@example.com",
"firstName": "John",
"lastName": "Doe"
},
"partnerId": "550e8400-e29b-41d4-a716-446655440001",
"scopes": ["monitorable:read", "monitorable:write", "event:read"],
"createdAt": "2024-01-15T10:30:00Z",
"updatedAt": "2024-01-20T14:45:00Z"
}
Member Scopes
Scopes define what actions a member can perform. Each scope grants permission for specific operations:
Resource Scopes
| Scope | Description |
|---|---|
application:read | View API applications and their details |
application:write | Create, update, and delete API applications |
event:read | View events and event details |
member:read | View organization members |
member:write | Invite, update, and remove members |
monitorable:read | View monitorables and their details |
monitorable:write | Create, update, and delete monitorables |
monitorable:token:write | Generate access tokens for monitorables |
webhook:read | View webhook configurations |
webhook:write | Create, update, and delete webhooks |
Scope Categories
Scopes follow a consistent pattern:
:readscopes allow viewing resources:writescopes allow creating, updating, and deleting resources
Invitation Workflow
Members are added to an organization through an invitation process:
Invitation Process
- Create Invitation: An existing member with
member:writescope creates an invitation specifying the email and scopes - Receive Invitation: The invitee receives an email with a link to accept the invitation
- Accept Invitation: The invitee enters the 4-digit code from the invitation email
- Account Setup: If the invitee doesn't have a Hyperion account, they create one during acceptance
- Member Created: Upon acceptance, the user becomes a member of the organization with the assigned scopes
Invitation Response
When you create an invitation, you receive:
{
"id": "550e8400-e29b-41d4-a716-446655440000",
"email": "john.doe@example.com",
"code": "1234",
"partnerId": "550e8400-e29b-41d4-a716-446655440001",
"role": "PARTNER",
"scopes": ["monitorable:read", "monitorable:write", "event:read"],
"expiresAt": "2024-02-15T10:30:00Z",
"invitationUrl": "https://partners.hyperion.adt.com/member-invitations/550e8400-e29b-41d4-a716-446655440000"
}
Invitations expire after a set period. If an invitation expires, create a new one for the intended member.
Use Cases
Onboarding Team Members
When a new employee joins your organization, invite them with appropriate scopes:
{
"email": "new.employee@yourcompany.com",
"scopes": ["monitorable:read", "event:read"]
}
Role-Based Access Control
Create different permission sets for different roles:
Operations Team - Full access to monitorables and events:
{
"scopes": [
"monitorable:read",
"monitorable:write",
"monitorable:token:write",
"event:read"
]
}
Development Team - API and webhook management:
{
"scopes": [
"application:read",
"application:write",
"webhook:read",
"webhook:write"
]
}
Team Lead - Full member management:
{
"scopes": ["member:read", "member:write", "monitorable:read", "event:read"]
}
Updating Permissions
When a team member's responsibilities change, update their scopes:
{
"scopes": [
"monitorable:read",
"monitorable:write",
"monitorable:token:write",
"event:read",
"webhook:read",
"webhook:write"
]
}
Related Resources
API Reference
Members
- List Members - Get all organization members
- Get Member - Retrieve member details
- Update Member - Update member scopes
- Delete Member - Remove a member
Member Invitations
- Create Invitation - Invite a new member
- List Invitations - View pending invitations
- Delete Invitation - Cancel an invitation