A guard on the per-load membership mirror write. If the visitor is platform staff and is not an actual member of the account they are viewing, the mirror write is skipped. Their synthetic memberships still appear in their own account switcher, so the interface reflects what they can already do — but nothing is persisted into the customer's roster.
Also called: support appears in my team list · who is this person in our team · member count wrong
- 1Every app load self-heals the caller's membership row — except for a staff-only visit.
- 2A staff-only visit is detected as: not the owner, holds the enter-accounts capability, has an account resolved, and has no real membership in it.
- 3Synthetic memberships for the switcher are built in memory only and explicitly not written to the roster table.
- 4The owner keeps his existing behaviour.
The comment states what would otherwise happen: that table 'is the tenant's own roster — it drives their Team list and the member counts on /platform — and a support call would otherwise silently enrol a Leads 2 Build employee as an employee of the builder.' The synthetic memberships are labelled in the same file as deliberately non-persistent: 'a staff member helping a builder is not a member of that builder's company.'
- A support visit silently enrolled a vendor employee in a customer's roster.
- Member counts and seat usage were inflated by vendor visits.
- The customer's team list showed people they had never hired.
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →