Build a useful investigation brief
Map link and session
Record the invitation route, recipient session state, workspace identifier available to the app, and redirect sequence without exposing the invitation token. Compare a signed-out entry with an existing account. Note where the page chooses an account or workspace context.
Compare durable membership
After acceptance, inspect authorized synthetic membership and role records and compare them with the invitation’s intended role. Check duplicate or already-accepted paths. If a membership is not created, distinguish a safe rejection from a silent redirect or an unavailable record.
Test expiry and boundaries
Use expired, revoked, duplicate, wrong-account, and wrong-workspace fixtures where supported. Confirm each path avoids leaking workspace details to an unintended person. Record whether a link can be retried safely and which owner controls the recovery action.
What to carry forward
The investigation is ready when link entry, session choice, invitation state, membership result, and redirect context are traceable for one reproducible variant. Deliver the first mismatch and keep copy ambiguity separate from any permission or tenancy issue.
Keep the decision with the work.
Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.
Create an account See the product workflow