# NewUserInput

input type

Create-input for a User. The tenant (org group — the User parent) is derived SERVER-SIDE from the principal — NEVER supplied here. accountId names the EXISTING Account to bind (miss → NOT_FOUND/CONSTRUCT; doomed → CONFLICT/REF_STATE; a restricted account is bindable). At most ONE User per (account × group): a live holder refuses CONFLICT/IDENTITY_TAKEN naming it; a DOOMED holder's binding is taken over atomically. orgRoles is required but MAY be empty; refs validated STRICT (in-tenant + active).

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `caption` | [String](/types/#scalars) | no | Optional: when omitted the per-type default applies — the constant 'User'; when supplied it must be non-blank. |
| `accountId` | [ID](/types/#scalars) `ID!` | yes | The EXISTING Account this user binds — immutable thereafter. |
| `orgRoles` | [UserOrgRolesInput](/types/UserOrgRolesInput/) `[UserOrgRolesInput!]!` | yes | The initial role-assignment set; may be empty (no org association yet). |

## Used by

- [createUser](/reference/user/createUser/)
