Agent skill

Organization Best Practices

by ever-works in ever-works/ever-works

Configure multi-tenant organizations, manage members and invitations, define custom roles and permissions, set up teams, and implement RBAC using Better Auth's organization plugin.

AGPL-3.0Auto-check passedBackend & APIs

Install Organization Best Practices

skills CLI
$ npx skills add ever-works/ever-works --skill organization-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ever-works/ever-works organization-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ever-works/ever-works.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/organization-best-practices .claude/skills/organization-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
organization-best-practices
GitHub stars
162
Used in
2 other repos
Token cost
~2.6k tokens
SKILL.md length
400 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Configure multi-tenant organizations, manage members and invitations, define custom roles and permissions, set up teams, and implement RBAC using Better Auth's organization plugin.

  • Works in 4 steps: Add organization() plugin to server config → Add organizationClient() plugin to… → Run npx @better-auth/cli migrate → …
  • Users need org setup
  • SKILL.md covers Setup, Creating Organizations, Active Organizations and Members, plus 7 more sections
  • Calls npx

What it does

Organization Best Practices is an agent skill from ever-works/ever-works. Configure multi-tenant organizations, manage members and invitations, define custom roles and permissions, set up teams, and implement RBAC using Better Auth's organization plugin. Use when users need org setup, team management, member roles, access control, or the Better Auth organization plugin.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC and Multi-tenancy. It works with Better Auth. The repository describes itself as: Ever® Works™ - The Workshop for AI. An open agentic runtime that autonomously researches, ships, and maintains entire businesses, 24/7 - https://ever.works. The licence is AGPL-3.0.

When your agent uses it

  • Users need org setup
  • Team management
  • The Better Auth organization plugin

Example prompts

  • “/organization-best-practices”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Add organization() plugin to server config
  2. Add organizationClient() plugin to client config
  3. Run npx @better-auth/cli migrate
  4. Verify: check that organization, member, invitation tables exist in your database

What it can do on your machine

Read from SKILL.md and the folder at commit 330f7b9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Organization Best Practices loads about 2.6k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 400 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ever-works/ever-works at commit 330f7b9, republished under its AGPL-3.0 licence (© ever-works). 400 words, ~2,609 tokens.

Download SKILL.mdSave it as .claude/skills/organization-best-practices/SKILL.md (or your agent's skills folder).
name
organization-best-practices
description
Configure multi-tenant organizations, manage members and invitations, define custom roles and permissions, set up teams, and implement RBAC using Better Auth's organization plugin. Use when users need org setup, team management, member roles, access control, or the Better Auth organization plugin.

Setup

  1. Add organization() plugin to server config
  2. Add organizationClient() plugin to client config
  3. Run npx @better-auth/cli migrate
  4. Verify: check that organization, member, invitation tables exist in your database
ts
import { betterAuth } from 'better-auth';
import { organization } from 'better-auth/plugins';

export const auth = betterAuth({
	plugins: [
		organization({
			allowUserToCreateOrganization: true,
			organizationLimit: 5, // Max orgs per user
			membershipLimit: 100 // Max members per org
		})
	]
});
Client-Side Setup
ts
import { createAuthClient } from 'better-auth/client';
import { organizationClient } from 'better-auth/client/plugins';

export const authClient = createAuthClient({
	plugins: [organizationClient()]
});

Creating Organizations

The creator is automatically assigned the owner role.

ts
const createOrg = async () => {
	const { data, error } = await authClient.organization.create({
		name: 'My Company',
		slug: 'my-company',
		logo: 'https://example.com/logo.png',
		metadata: { plan: 'pro' }
	});
};
Controlling Organization Creation

Restrict who can create organizations based on user attributes:

ts
organization({
	allowUserToCreateOrganization: async (user) => {
		return user.emailVerified === true;
	},
	organizationLimit: async (user) => {
		// Premium users get more organizations
		return user.plan === 'premium' ? 20 : 3;
	}
});
Creating Organizations on Behalf of Users

Administrators can create organizations for other users (server-side only):

ts
await auth.api.createOrganization({
	body: {
		name: 'Client Organization',
		slug: 'client-org',
		userId: 'user-id-who-will-be-owner' // `userId` is required
	}
});

Note: The userId parameter cannot be used alongside session headers.

Active Organizations

Stored in the session and scopes subsequent API calls. Set after user selects one.

ts
const setActive = async (organizationId: string) => {
	const { data, error } = await authClient.organization.setActive({
		organizationId
	});
};

Many endpoints use the active organization when organizationId is not provided (listMembers, listInvitations, inviteMember, etc.).

Use getFullOrganization() to retrieve the active org with all members, invitations, and teams.

Members

Adding Members (Server-Side)
ts
await auth.api.addMember({
	body: {
		userId: 'user-id',
		role: 'member',
		organizationId: 'org-id'
	}
});

For client-side member additions, use the invitation system instead.

Assigning Multiple Roles
ts
await auth.api.addMember({
	body: {
		userId: 'user-id',
		role: ['admin', 'moderator'],
		organizationId: 'org-id'
	}
});
Removing Members

Use removeMember({ memberIdOrEmail }). The last owner cannot be removed — assign ownership to another member first.

Updating Member Roles

Use updateMemberRole({ memberId, role }).

Membership Limits
ts
organization({
	membershipLimit: async (user, organization) => {
		if (organization.metadata?.plan === 'enterprise') {
			return 1000;
		}
		return 50;
	}
});

Invitations

Setting Up Invitation Emails
ts
import { betterAuth } from 'better-auth';
import { organization } from 'better-auth/plugins';
import { sendEmail } from './email';

export const auth = betterAuth({
	plugins: [
		organization({
			sendInvitationEmail: async (data) => {
				const { email, organization, inviter, invitation } = data;

				await sendEmail({
					to: email,
					subject: `Join ${organization.name}`,
					html: `
            <p>${inviter.user.name} invited you to join ${organization.name}</p>
            <a href="https://yourapp.com/accept-invite?id=${invitation.id}">
              Accept Invitation
            </a>
          `
				});
			}
		})
	]
});
Sending Invitations
ts
await authClient.organization.inviteMember({
	email: 'newuser@example.com',
	role: 'member'
});
Shareable Invitation URLs
ts
const { data } = await authClient.organization.getInvitationURL({
	email: 'newuser@example.com',
	role: 'member',
	callbackURL: 'https://yourapp.com/dashboard'
});

// Share data.url via any channel

This endpoint does not call sendInvitationEmail — handle delivery yourself.

Invitation Configuration
ts
organization({
	invitationExpiresIn: 60 * 60 * 24 * 7, // 7 days (default: 48 hours)
	invitationLimit: 100, // Max pending invitations per org
	cancelPendingInvitationsOnReInvite: true // Cancel old invites when re-inviting
});

Roles & Permissions

Default roles: owner (full access), admin (manage members/invitations/settings), member (basic access).

Checking Permissions
ts
const { data } = await authClient.organization.hasPermission({
	permission: 'member:write'
});

if (data?.hasPermission) {
	// User can manage members
}

Use checkRolePermission({ role, permissions }) for client-side UI rendering (static only). For dynamic access control, use the hasPermission endpoint.

Teams

Enabling Teams
ts
import { organization } from 'better-auth/plugins';

export const auth = betterAuth({
	plugins: [
		organization({
			teams: {
				enabled: true
			}
		})
	]
});
Creating Teams
ts
const { data } = await authClient.organization.createTeam({
	name: 'Engineering'
});
Managing Team Members

Use addTeamMember({ teamId, userId }) (member must be in org first) and removeTeamMember({ teamId, userId }) (stays in org).

Set active team with setActiveTeam({ teamId }).

Show full SKILL.md (148 more words)Show less
Team Limits
ts
organization({
	teams: {
		maximumTeams: 20, // Max teams per org
		maximumMembersPerTeam: 50, // Max members per team
		allowRemovingAllTeams: false // Prevent removing last team
	}
});

Dynamic Access Control

Enabling Dynamic Access Control
ts
import { organization } from 'better-auth/plugins';
import { dynamicAccessControl } from '@better-auth/organization/addons';

export const auth = betterAuth({
	plugins: [
		organization({
			dynamicAccessControl: {
				enabled: true
			}
		})
	]
});
Creating Custom Roles
ts
await authClient.organization.createRole({
	role: 'moderator',
	permission: {
		member: ['read'],
		invitation: ['read']
	}
});

Use updateRole({ roleId, permission }) and deleteRole({ roleId }). Pre-defined roles (owner, admin, member) cannot be deleted. Roles assigned to members cannot be deleted until reassigned.

Lifecycle Hooks

Execute custom logic at various points in the organization lifecycle:

ts
organization({
	hooks: {
		organization: {
			beforeCreate: async ({ data, user }) => {
				// Validate or modify data before creation
				return {
					data: {
						...data,
						metadata: { ...data.metadata, createdBy: user.id }
					}
				};
			},
			afterCreate: async ({ organization, member }) => {
				// Post-creation logic (e.g., send welcome email, create default resources)
				await createDefaultResources(organization.id);
			},
			beforeDelete: async ({ organization }) => {
				// Cleanup before deletion
				await archiveOrganizationData(organization.id);
			}
		},
		member: {
			afterCreate: async ({ member, organization }) => {
				await notifyAdmins(organization.id, `New member joined`);
			}
		},
		invitation: {
			afterCreate: async ({ invitation, organization, inviter }) => {
				await logInvitation(invitation);
			}
		}
	}
});

Schema Customization

Customize table names, field names, and add additional fields:

ts
organization({
	schema: {
		organization: {
			modelName: 'workspace', // Rename table
			fields: {
				name: 'workspaceName' // Rename fields
			},
			additionalFields: {
				billingId: {
					type: 'string',
					required: false
				}
			}
		},
		member: {
			additionalFields: {
				department: {
					type: 'string',
					required: false
				},
				title: {
					type: 'string',
					required: false
				}
			}
		}
	}
});

Security Considerations

Owner Protection
  • The last owner cannot be removed from an organization
  • The last owner cannot leave the organization
  • The owner role cannot be removed from the last owner

Always ensure ownership transfer before removing the current owner:

ts
// Transfer ownership first
await authClient.organization.updateMemberRole({
	memberId: 'new-owner-member-id',
	role: 'owner'
});

// Then the previous owner can be demoted or removed
Organization Deletion

Deleting an organization removes all associated data (members, invitations, teams). Prevent accidental deletion:

ts
organization({
	disableOrganizationDeletion: true // Disable via config
});

Or implement soft delete via hooks:

ts
organization({
	hooks: {
		organization: {
			beforeDelete: async ({ organization }) => {
				// Archive instead of delete
				await archiveOrganization(organization.id);
				throw new Error('Organization archived, not deleted');
			}
		}
	}
});
Invitation Security
  • Invitations expire after 48 hours by default
  • Only the invited email address can accept an invitation
  • Pending invitations can be cancelled by organization admins

Complete Configuration Example

ts
import { betterAuth } from 'better-auth';
import { organization } from 'better-auth/plugins';
import { sendEmail } from './email';

export const auth = betterAuth({
	plugins: [
		organization({
			// Organization limits
			allowUserToCreateOrganization: true,
			organizationLimit: 10,
			membershipLimit: 100,
			creatorRole: 'owner',

			// Slugs
			defaultOrganizationIdField: 'slug',

			// Invitations
			invitationExpiresIn: 60 * 60 * 24 * 7, // 7 days
			invitationLimit: 50,
			sendInvitationEmail: async (data) => {
				await sendEmail({
					to: data.email,
					subject: `Join ${data.organization.name}`,
					html: `<a href="https://app.com/invite/${data.invitation.id}">Accept</a>`
				});
			},

			// Hooks
			hooks: {
				organization: {
					afterCreate: async ({ organization }) => {
						console.log(`Organization ${organization.name} created`);
					}
				}
			}
		})
	]
});

© ever-works, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/organization-best-practices of ever-works/ever-works.

Open the folder on GitHubat commit 330f7b9

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in ever-works/ever-works, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Organization Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Organization Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Organization Best Practices this skillever-works/ever-works1622 repos~2.6kAutomated safety check: PassAGPL-3.0
Abp Authorizationabpframework/abp14k—~1.3kAutomated safety check: PassLGPL-3.0
Django Access Reviewgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Backend AI Guidelablup/backend.ai-webui1331 repos~1.8kAutomated safety check: PassLGPL-3.0
Arandu Shared Modules Guidearandu-io/arandu281—~1.8kAutomated safety check: PassMIT

Similar skills

  • Abp Authorization

    abpframework/abp

    ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

    14k GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Backend AI Guide

    lablup/backend.ai-webui

    Expert guide for Backend.AI distributed computing platform. An agent skill from lablup/backend.ai-webui.

    133 GitHub starsUsed in 1 repo~1.8k tokens
    Backend & APIsAuto-check passed
  • Decides whether a feature belongs in the application or in one of five shared Arandu modules before adding permissions, wallets, tags, Markdown rendering or API docs.

    281 GitHub stars~1.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Cognee Permissions

    topoteretes/cognee

    A skill your agent uses when working with cognee's users, permissions, and multi-tenancy — creating users, tenants and roles, sharing datasets (read/write/delete/share grants), acting as a specific…

    32k GitHub stars~3.6k tokensUpdated today
    Backend & APIsAuto-check passed

More from ever-works/ever-works

All 14 skills in this repo
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    162 GitHub starsUsed in 18 repos~4k tokens
    Auto-check passed
  • Accessibility

    ever-works/ever-works

    Audit and improve web accessibility following WCAG 2.2 guidelines.

    162 GitHub starsUsed in 6 repos~3.2k tokens
    Auto-check passed
  • Tailwind CSS Patterns

    ever-works/ever-works

    Provides comprehensive Tailwind CSS utility-first styling patterns including responsive design, layout utilities, flexbox, grid, spacing, typography, colors, and modern CSS best practices.

    162 GitHub starsUsed in 3 repos~1.6k tokens
    Auto-check: notes
  • SEO

    ever-works/ever-works

    Optimize for search engine visibility and ranking. An agent skill from ever-works/ever-works.

    162 GitHub starsUsed in 10 repos~2.9k tokens
    Auto-check passed
  • Nodejs Express Server

    ever-works/ever-works

    Build production-ready Express.js servers with middleware, authentication, routing, and database integration.

    162 GitHub stars~965 tokensUpdated today
    Auto-check passed
  • Tailwind V4 Shadcn

    ever-works/ever-works

    Production-tested setup for Tailwind CSS v4 with shadcn/ui, Vite, and React.

    162 GitHub starsUsed in 2 repos~3.8k tokens
    Auto-check passed

Works with

Categories

Questions about Organization Best Practices

What does Organization Best Practices do?

Configure multi-tenant organizations, manage members and invitations, define custom roles and permissions, set up teams, and implement RBAC using Better Auth's organization plugin. Organization Best Practices is an agent skill from ever-works/ever-works. Configure multi-tenant organizations, manage members and invitations, define custom roles and permissions, set up teams, and implement RBAC using Better Auth's organization plugin.

When should I use Organization Best Practices?

Organization Best Practices fits situations like: users need org setup; team management; the Better Auth organization plugin.

How do I install Organization Best Practices in Claude Code?

Run `npx skills add ever-works/ever-works --skill organization-best-practices -a claude-code`. Or copy the skill folder (.agents/skills/organization-best-practices in ever-works/ever-works) into .claude/skills/organization-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Organization Best Practices in Codex?

Run `npx skills add ever-works/ever-works --skill organization-best-practices -a codex`. Or copy the skill folder (.agents/skills/organization-best-practices in ever-works/ever-works) into .agents/skills/organization-best-practices in your project. Codex loads it when a task matches its description.

Can I use Organization Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ever-works/ever-works --skill organization-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/organization-best-practices, .gemini/skills/organization-best-practices, .github/skills/organization-best-practices and .opencode/skills/organization-best-practices in your project.

What does Organization Best Practices need to run?

Going by SKILL.md and its folder, Organization Best Practices needs the command-line tools its instructions call (npx). Our summary lists: Node.js.

Does Organization Best Practices access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Organization Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Organization Best Practices use?

Organization Best Practices is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Organization Best Practices use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Organization Best Practices?

Skills that share tags, products or a category with Organization Best Practices: Abp Authorization (abpframework/abp, 14k stars), Django Access Review (getsentry/skills, 1k stars), Supercheck Security Auth (supercheck-io/supercheck, 215 stars) and Backend AI Guide (lablup/backend.ai-webui, 133 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Organization Best Practices?

ever-works (a GitHub organization) maintains it in ever-works/ever-works, which has 162 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 10, 2026.

Source: ever-works/ever-works on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.