Change a member's role on a business account
Platform-credential counterpart of the SDK updateMemberRole. Governance is bypassed — the role change is always applied directly, never proposed. Cannot assign owner; ownership moves only via transferOwnership. No TokenScopes.BusinessAccountsWrite scope yet — access is gated by the caller’s role.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
ID of the environment
36^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"95b11417-f18f-457f-8804-68e361f9164f"
ID of the business account
36^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"95b11417-f18f-457f-8804-68e361f9164f"
UUID of the user
36^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"95b11417-f18f-457f-8804-68e361f9164f"
Body
Changes a member's role to any role the account defines — a built-in (admin, viewer) or a customer-defined one, and between two customer-defined ones. Owner is never a target — ownership moves via transferOwnership.
A role that can be directly assigned to a member: a built-in (admin, viewer) or a customer-defined role the account has defined. owner is excluded — ownership moves only via transferOwnership.
Not an enum, because the set is per-account: a caller can grant any role from GET /roles. Whether the role exists is the enclave's to answer, not this schema's — the pattern only rejects names that could never be one. A role the account has not defined is refused with UNKNOWN_ROLE.
A customer-defined role grants exactly what it inherits, so cfo inherits admin is an admin with a distinguishable name.
Case-insensitive on input — CFO and cfo name the same role. The server normalizes to lowercase before comparing or storing, so the pattern accepts both cases here even though a held/stored role name (HeldBusinessAccountMemberRole) is always lowercase.
^[a-zA-Z0-9](?:[a-zA-Z0-9_-]{0,30}[a-zA-Z0-9])?$"cfo"
Response
Member role changed
Admin-reach membership in a business account
36^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"95b11417-f18f-457f-8804-68e361f9164f"
36^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"95b11417-f18f-457f-8804-68e361f9164f"
36^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"95b11417-f18f-457f-8804-68e361f9164f"
The role a member actually holds: a built-in (owner, admin, viewer) or a customer-defined role the account has defined. Wider than AssignableBusinessAccountRoleName because a held role can be owner, which cannot be assigned directly.
^[a-z0-9](?:[a-z0-9_-]{0,30}[a-z0-9])?$"cfo"
Member's verified email; null when they have none
The member's actual customer-defined role, when role names one; null for a built-in role
Dashboard-only: this member's most recent session creation time. Null when they have never completed authentication (e.g. still mid-invite).