companyId as a query parameter — it is injected from the key's binding.| Role | What They Can Do |
|---|---|
| Super | Full access. Company creator. |
| Admin | Almost everything. Cannot remove super admins. |
| Manager | Manage teams if owner. Invite/remove people below. |
| SPV | Supervisor. Limited team management. |
| Member | Read-only. Can comment on things they create. |
| Guest | Read-only. |
402 Payment Required.