Teams
Multi-tenant organization boundaries, role-based access, and member collaboration.
VibeKit includes complete multi-tenant team architecture out of the box. Whether your product serves individual creators or collaborative enterprise teams, VibeKit handles organization boundaries, membership roles, and member invitations so you can build multi-user SaaS quickly and securely.
Multi-Tenant Workspaces by Default
Every workspace in VibeKit represents an isolated organizational boundary. All product data—such as projects, documents, billing subscriptions, and uploaded assets—links directly to a specific Team:
- Workspace Isolation: Data belongs to the organization rather than a single user account. When a team member leaves, the team's data remains intact for remaining members.
- Instant Team Switching: Users who belong to multiple teams can switch active workspaces from the application sidebar or header without logging out.
- Team Profiles: Each team features a customizable display name, unique URL slug, and branded avatar stored securely in your storage bucket.
Role-Based Access and Safe Delegation
VibeKit provides built-in team roles with clear permissions:
| Role | Permissions and Capabilities |
|---|---|
| OWNER | Full administrative control. Can manage billing subscriptions, change team settings, invite or remove members, assign roles, and delete the workspace. |
| MEMBER | Standard operational access. Can view team data, create and edit team resources, and collaborate within features granted by the team's active subscription. |
Role checks are enforced directly in your API layer using tRPC context and server-side authorization guards. The client UI dynamically adapts to show or hide administrative settings based on the user's active role.
Team Invitations and Email Onboarding
Inviting colleagues to a workspace is completely automated:
- Email Invitation Dispatch: Team owners enter a colleague's email address and select their assigned role.
- Secure Token Generation: VibeKit generates a cryptographically random, time-limited invitation token and saves the invitation in PostgreSQL.
- Branded React Email: An automated invitation email is rendered using the
TeamInvitation.tsxReact Email template and sent via your configured email provider. - Frictionless Acceptance: When the invitee clicks the link, VibeKit validates the token. Existing users join the team immediately; new users are guided through account registration and automatically added upon sign-up.
Bulletproof Tenant Isolation on the Server
Client applications can send any team identifier in headers or request payloads. VibeKit prevents cross-tenant data leaks with strict server-side rules:
- Session Validation: Every API procedure verifies that the authenticated user actually holds an active membership in the target team before executing queries.
- Scoped Database Queries: Queries and mutations automatically include
where: { teamId }to ensure users can never view, edit, or delete another team's records. - Ownership Integrity: Foreign-tenant requests fail immediately with an authorization error, ensuring total isolation between customer organizations.
Directing Your Agent on Team Features
When asking your coding agent to build team-scoped workflows, instruct it to follow VibeKit's tenant isolation conventions:
Create a new 'Projects' feature under 'apps/web/features/projects'.
Ensure all database records link to 'teamId' with a foreign key to the Team model.
In the tRPC router, verify that the authenticated user belongs to the active team before returning any project lists.
Allow only users with the 'OWNER' role to archive or delete a project.