Accounts and tenancy

Model organizations, memberships, invitations, ownership, active-account switching, and fail-closed data scope.

Supported approaches

Memberships and roles

available

Resolve active membership and application-defined roles for every account-scoped operation.

Packages

@playstack/accounts@playstack/nest-accounts

Frameworks and integrations

Invitations

available

Issue expiring invitation tokens through an application-owned delivery bridge.

Active-account switching

available

Reissue account-scoped sessions and synchronize the selected account in application UI.

Ownership transfer

available

Propose, deliver, accept, or cancel a single-use ownership transfer while preserving the one-owner invariant.

Recoverable deletion

available

Hide an account immediately, permit restoration during grace, then run bounded application cascades before purge.

Frameworks and integrations

Frameworks and integrations

framework

React

Headless domain bindings plus optional Chakra application and admin compositions, with server authority kept outside the client.

framework

Next.js

Compose Playstack server contracts, React bindings, SSR handoff, and route adapters at the Next.js application edge.

framework

NestJS

Connect portable Playstack capabilities to dependency injection, guards, decorators, request context, workers, and lifecycle hooks.

integration

Prisma

Persist Playstack capabilities through explicit application-owned Prisma clients, transactions, and managed schema fragments.

integration

Amazon SES

Deliver rendered messages and SES templates through an application-configured AWS SDK client.

integration

Mailgun

Deliver rendered messages or stored Mailgun templates through an explicit regional provider client.

integration

Postmark

Deliver rendered Playstack mail or Postmark provider templates through an explicit driver and native client escape hatch.

integration

Resend

Deliver transactional mail and synchronize consent-aware audience contacts through explicit Resend adapters.

integration

SendGrid

Deliver rendered messages and dynamic templates through an isolated SendGrid mail client.

integration

SMTP

Deliver portable rendered email through an application-configured Nodemailer transport.

Package reference

@playstack/accounts

Keep tenant context explicit

Accounts model the tenant a user is acting within and the membership that permits that scope. Framework adapters carry the validated result; they do not infer account access from request parameters.

Compose from the request inward

Authenticate first, resolve account membership second, then apply roles and fail-closed persistence scope before executing product behavior.

Compose the account lifecycle

The service exposes member and invitation lists, account name/slug updates, self-service leaving, and account-scoped session switching. Ownership changes use a delivered single-use proposal rather than an immediate administrative mutation, keeping the owner pointer and both membership roles in one transaction.

Signup can register userRegistrationHandler() on auth’s transactional registration event to create the initial account and owner membership before the user commits. Recoverable deletion hides an account immediately, supports restoration during the configured grace period, and leaves scheduling plus cross-database erasure to the application.

Restrict service policy without replacing the core

administration: 'owners-only' restricts membership administration; the default remains owners-and-admins. mutationPolicy.assertAllowed(input, transaction) can enforce product-owned personal-account rules before writes. Hooks restrict built-in permissions rather than grant extra authority, and must use the supplied transaction.

slugPolicy supports normalization and reserved-slug decisions. createAccountPolicy() provides named permissions for the Nest guard; service policy and resource authorization remain separate. Single-owner behavior is still the shipped model: hooks do not implement multi-owner accounts or automatic personal-to-team conversion.

An optional Nest resolveRequestAccount strategy supports user-wide sessions with current membership checks. A session already scoped to an account cannot select another; ordinary account switching retains its session-rotation behavior.

Go

Playstack Pro tag
OriginsPricingBlogNewsletterChangelogStatusRoadmap
ContributorsCommunityIn Use ShowcaseCase StudiesPartnersSponsors
FAQsSupportContact

© 2026 Playstack. All rights reserved.

With OSS
Terms of ServicePrivacy PolicyCookie PolicyImprint

By

Commune Software