NewCollaboratorInput
input type
Create-input for a Collaborator. The tenant (org group) is derived SERVER-SIDE from the principal. ⚠ NO password and NO invite token here — a created Collaborator is CREDENTIAL-LESS (it cannot log in) until issueCollaboratorInvite mints the show-once bootstrap token and the external party accepts it. orgRoles is required but MAY be empty; refs validated STRICT (in-tenant + active — the gate VERBATIM).
Fields
| Field | Type | Required | Notes |
|---|---|---|---|
caption | String | no | Optional: when omitted the per-type default applies — the display name when given, else the NORMALIZED email (the identity line); when supplied it must be non-blank. |
email | String String! | yes | The login identity — normalized server-side; the (group × email) UNIQ marker reserves in the create transaction. |
displayName | String | no | No further notes. |
orgRoles | UserOrgRolesInput [UserOrgRolesInput!]! | yes | The initial role-assignment set; may be empty (no org access yet). |