# NewCollaboratorInput

input type

Create-input for a Collaborator. The tenant (org group) is derived SERVER-SIDE from the principal. ⚠ NO password and NO invite token here — a created Collaborator is CREDENTIAL-LESS (it cannot log in) until issueCollaboratorInvite mints the show-once bootstrap token and the external party accepts it. orgRoles is required but MAY be empty; refs validated STRICT (in-tenant + active — the gate VERBATIM).

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `caption` | [String](/types/#scalars) | no | Optional: when omitted the per-type default applies — the display name when given, else the NORMALIZED email (the identity line); when supplied it must be non-blank. |
| `email` | [String](/types/#scalars) `String!` | yes | The login identity — normalized server-side; the (group × email) UNIQ marker reserves in the create transaction. |
| `displayName` | [String](/types/#scalars) | no | No further notes. |
| `orgRoles` | [UserOrgRolesInput](/types/UserOrgRolesInput/) `[UserOrgRolesInput!]!` | yes | The initial role-assignment set; may be empty (no org access yet). |

## Used by

- [createCollaborator](/reference/collaborator/createCollaborator/)
