> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentlinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Set member access

> Change one member's role, their project grant, or both.

`set_member_access`

Change one member's role, their project grant, or both. A grant of null means every project. Refusals worth knowing: the last owner cannot be demoted, nobody can raise their own role or outrank their actor, and an owner cannot be scoped to specific projects because a scoped owner can lock a project away from everyone. A member's grant is the CEILING on every key they hold, so narrowing it narrows their existing keys immediately.

<Note>Hosted MCP registration verified. These schemas describe the development contract; confirm supported inputs with tools/list. Generic CLI/HTTP calls require a matching development server. Configure LINKTRAIL\_API\_URL; production does not expose these command routes.</Note>

| Access           | Behavior                                                   |
| ---------------- | ---------------------------------------------------------- |
| `projects:write` | Writes or admits work; can change or remove existing state |

Reading saved data does not start a verification job. Mutations can change saved records or access; the effects below apply.

## Example request

Connect through [MCP](/guides/connect-mcp), [CLI](/guides/connect-cli), or [HTTP](/guides/connect-http). Replace example identifiers with records from your workspace.

<CodeGroup>
  ```json MCP theme={null}
  {
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/call",
    "params": {
      "name": "set_member_access",
      "arguments": {
        "userId": "user_example",
        "role": "viewer"
      }
    }
  }
  ```

  ```bash CLI theme={null}
  linktrail call set_member_access --args '{"userId":"user_example","role":"viewer"}'
  ```

  ```bash HTTP theme={null}
  curl "$LINKTRAIL_API_URL/v1/commands/set_member_access" \
    -H "Authorization: Bearer $LINKTRAIL_API_KEY" \
    -H 'Content-Type: application/json' \
    --data '{"userId":"user_example","role":"viewer"}'
  ```
</CodeGroup>

## Returned result

Illustrative data validated against the documented response schema. IDs and dates are examples, not a live account capture. MCP returns this data in `structuredContent` and in a text content block; generic HTTP and CLI return the JSON result directly.

```json theme={null}
{
  "user_id": "user_example",
  "role": "viewer",
  "project_ids": [
    "pr_example"
  ],
  "changed_at": "2026-09-13T12:00:00.000Z"
}
```

## Input fields

Omit optional fields when you do not want to supply them. Null is accepted only where listed. Unknown input properties are rejected.

| Field        | Type         | Presence | Meaning and constraints                                                                                          |
| ------------ | ------------ | -------- | ---------------------------------------------------------------------------------------------------------------- |
| `userId`     | string       | Required | Identifier of the user returned by its create or list operation. minLength: 1; maxLength: 128                    |
| `role`       | string       | Optional | Workspace access role; cannot exceed the acting member’s authority. values: "owner", "admin", "member", "viewer" |
| `projectIds` | array / null | Optional | Accessible project IDs. Where nullable, null grants all projects.                                                |

### Validation and omitted values

Supply role, projectIds or both. Omitted fields preserve current access; explicit projectIds:null means workspace-wide access.

The last owner cannot be demoted, an owner cannot be project-limited, and the acting member cannot raise their own role or grant authority they lack.

## Output fields

Fields inside optional or nullable parents apply only when that parent exists. [Common schema conventions](/reference/schemas) explain evidence states, empty lists and extensions.

| Field         | Type         | Presence | Meaning and constraints                                                       |
| ------------- | ------------ | -------- | ----------------------------------------------------------------------------- |
| `user_id`     | string       | Required | user id recorded for this result.                                             |
| `role`        | string       | Required | role recorded for this result.                                                |
| `project_ids` | array / null | Required | Accessible project identifiers; null grants access to all workspace projects. |
| `changed_at`  | string       | Required | changed at recorded for this result.                                          |

[Download input schema](/schemas/set_member_access.input.json) · [Download output schema](/schemas/set_member_access.output.json)

## Errors and retries

This command is not annotated idempotent. After a timeout, inspect existing state before repeating a write.

See [error recovery](/reference/errors) for status, scope, cooldown, cursor and retry handling. Unknown observations are result data and do not establish loss.

## HTTP resource routes

These existing resource routes share the operation’s domain behavior. Their parameter placement, status and response envelope can differ from generic invocation. See [HTTP route details](/reference/http/routes).

| Method and route             | Success | Details                                       |
| ---------------------------- | ------- | --------------------------------------------- |
| `PATCH /v1/members/{userId}` | 200     | Remaining arguments go in a JSON object body. |

## Continue

[list\_members](/reference/commands/list_members)

Follow the [related workflow](/guides/connect-http), inspect [capability status](/capability-status), or return to the [command index](/reference/index).
