Skip to content

Change a company role

PATCH
/v1/companies/{id}/members/{userId}
curl --request PATCH \
--url https://beta-api.plune.ai/v1/companies/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/members/example \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "role": "admin" }'

An owner or an admin; only an owner makes, changes or unmakes an owner. The last owner stays one — make somebody else an owner first (409). A company role changes no project role: it decides the role somebody joins a project with, not the one they already hold.

id
required
string format: uuid
userId
required
string

The member’s userId

Media type application/json
object
role
required

What a member of a company may do (ADR 0038). owner and admin manage its people and add them to its projects — only an owner makes, unmakes or removes an owner, and only an owner deletes it; member and reader join its projects themselves. A company role opens no project: joining one gives the project role it maps to — owner and admin → owner, member → member, reader → reader.

string
Allowed values: owner admin member reader
Example
{
"role": "admin"
}

The member as they are now

Media type application/json
object
userId
required
string
email
required
string format: email
name

The display name (T3) — absent until the person has given one.

string
role
required

What a member of a company may do (ADR 0038). owner and admin manage its people and add them to its projects — only an owner makes, unmakes or removes an owner, and only an owner deletes it; member and reader join its projects themselves. A company role opens no project: joining one gives the project role it maps to — owner and admin → owner, member → member, reader → reader.

string
Allowed values: owner admin member reader
invitedBy

Who brought them in (a userId) — absent for the person who made the company.

string
createdAt
required
string format: date-time
Example
{
"userId": "6f1c2b3a-0000-4000-8000-0000000000a2",
"email": "[email protected]",
"role": "admin",
"invitedBy": "u-shop",
"createdAt": "2026-09-16T09:12:04.151Z"
}

Invalid body — one of the four roles

Media type application/json
object
error
required
string
Example generated
{
"error": "example"
}

No / invalid token or session

A member or a reader asked — or an admin reached for an owner

Media type application/json
object
error
required
string
Example
{
"error": "company owner only"
}

No such company among yours, or no such member in it

Media type application/json
object
error
required
string
Example generated
{
"error": "example"
}

The last owner

Media type application/json
object
error
required
string
Example
{
"error": "a company needs an owner — make somebody else one first"
}

Rate-limited: either the per-route throttle or a tenant quota. Retry-After carries the seconds until the window rolls over.

Media type application/json
object
error
required
string
Example generated
{
"error": "example"
}
Retry-After
integer

Seconds until the window rolls over