Agent-readable docs index: /docs/llms.txt. Full docs in one file: /docs/llms-full.txt. Download /docs/docs.zip to grep all markdown files locally.

Team Collaboration & Workspaces

Shaf features a multi-tenant organization architecture. Workspaces empower marketing squads, engineering teams, and agency partners to collaborate with strict isolation between client domains, analytics, links, and billing profiles.
In this tutorial, you will create a new organization, invite team members using transactional email invitations, and assign Role-Based Access Control (RBAC) permissions.

What You Will Build

Production Deliverable
  • Isolated Workspace: Dedicated team environment with separate link limits and domain quotas
  • Transactional Invites: Email onboarding with cryptographic, single-use invitation tokens
  • Role-Based Access Control (RBAC): Enforced permission boundaries across Owner, Admin, and Member
  • Audit Attribution: Activity logging attributing link creations and edits to individual teammates

Multi-Tenant Workspace Architecture

Each organization in Shaf acts as a completely isolated security boundary:
Your Shaf Account (Single Sign-On / OAuth) ├── [Personal Workspace] ──> Personal links & hobby domains └── [Acme Marketing (Org)] ├── Custom Domains (link.acme.com) ├── Shared Team Links & Tags ├── Real-time Click Analytics & CSV Exports ├── Team Members & Assigned RBAC Roles └── Scoped API Keys & Billing Invoices

Prerequisites

  • An active Shaf account.
  • Workspace creation privileges (available on all plans; additional seat limits vary by tier).

Step-by-Step Instructions

    Create a New Organization

    1. Open the Shaf Dashboard.
    2. Click the organization switcher dropdown located at the top of the left sidebar.
    3. Click Create Organization.
    4. In the dialog, enter your organization's name:
      Acme Marketing
    5. Click Create Organization. Shaf instantly provisions an isolated workspace with dedicated analytics, custom domains, and team quotas.

    Invite Team Members

    1. In the sidebar of your active workspace, click Settings -> Members.
    2. Click the Invite Member button in the top right.
    3. In the invitation modal, fill in:
      • Email Address: colleague@acme.com
      • Role: Select Admin or Member (see RBAC definitions below)
    4. Click Send Invitation.
    Transactional Email Delivery: Shaf dispatches a branded email invitation powered by Resend. The email contains a secure, single-use acceptance link (dash.shaf.app/invites/tok_...) cryptographically signed and valid for 7 days.

    Understand Member Roles & Permissions

    Shaf enforces three distinct role tiers to safeguard production links and domains:
    Owner
    Full Control
    • Manage billing, subscriptions & payment methods
    • Delete organization & transfer ownership
    • Add, verify & remove custom domains
    • Invite, modify & remove team members
    • Create, edit & delete all short links
    Admin
    Operational Lead
    • Add, verify & remove custom domains
    • Invite new team members (Admin & Member roles)
    • Create, edit & delete all short links
    • Generate organization API keys & webhooks
    • Export analytics reports & CSV data
    Member
    Contributor
    • Create, edit & organize short links
    • View real-time analytics & click maps
    • Export analytics CSV for own campaigns
    • Restricted: Cannot alter domains, members, or billing

    RBAC Permission Comparison Matrix

    PermissionOwnerAdminMember
    Create & Edit Short LinksYesYesYes
    View Analytics & Export CSVYesYesYes
    Add / Delete Custom DomainsYesYesNo
    Invite & Remove TeammatesYesYesNo
    Manage Billing & PaymentYesNoNo
    Delete OrganizationYesNoNo

    Accepting Invitations & Switching Workspaces

    1. When your teammate opens the email invitation and clicks the link, they will be prompted to authenticate or confirm acceptance.
    2. Once accepted, their account instantly receives access to the organization's links and domains.
    3. Teammates can toggle between workspaces at any time using the workspace switcher in the sidebar header.
    Fast Navigation: All link actions (creations, deletions, destination updates) record teammate attribution, providing complete team audit visibility.

Troubleshooting & Common Roadblocks

My teammate didn't receive the invitation email
Ask them to check their Spam or Promotions folders for emails from notifications@shaf.app. Alternatively, navigate to Settings -> Members -> Pending Invitations, click the action menu next to their email, and select Copy Invite Link to share the token with them directly.
The invite link says 'Invitation Expired'
Invitation tokens expire after 7 days for security. As an Owner or Admin, open the Members tab, revoke the expired invite, and click Resend Invitation to generate a fresh token.
How do I transfer organization ownership to a colleague?
The current Owner can navigate to Settings -> Members, locate the target Admin, and select Transfer Ownership. The current Owner will be stepped down to an Admin.

Checkpoint & Next Steps

🎉 Level 3 Milestone Complete!
Excellent! Your organization is fully equipped for multi-member collaboration and enterprise access control.
Final Lesson: Ready to automate? In Level 4, you will generate a developer API token and shorten links programmatically with REST API requests.