Tencent/WeKnora · error

tenant is not a member of this organization

Error message

tenant is not a member of this organization

What it means

Sentinel ErrTenantNotInOrg returned when resolving an org membership and the repository reports repository.ErrOrgMemberNotFound — the tenant is not (or no longer) a member of the organization, so org-scoped share operations are denied.

Source

Thrown at internal/application/service/organization.go:32

	"github.com/Tencent/WeKnora/internal/types/interfaces"
	"github.com/google/uuid"
)

// Default invite code validity in days; allowed values: 0 (never), 1, 7, 30
const DefaultInviteCodeValidityDays = 7

// DefaultMemberLimit is the default max tenant-members per organization (0 = unlimited)
const DefaultMemberLimit = 200

// ValidInviteCodeValidityDays are the allowed values for invite_code_validity_days
var ValidInviteCodeValidityDays = map[int]bool{0: true, 1: true, 7: true, 30: true}

var (
	ErrOrgNotFound           = errors.New("organization not found")
	ErrOrgPermissionDenied   = errors.New("permission denied for this organization")
	ErrCannotRemoveOwner     = errors.New("cannot remove organization owner tenant")
	ErrCannotChangeOwnerRole = errors.New("cannot change organization owner tenant role")
	ErrTenantNotInOrg        = errors.New("tenant is not a member of this organization")
	ErrInvalidRole           = errors.New("invalid role")
	ErrInviteCodeExpired     = errors.New("invite code has expired")
	ErrInvalidValidityDays   = errors.New("invite_code_validity_days must be 0, 1, 7, or 30")
	ErrOrgMemberLimitReached = errors.New("organization member limit reached")
	ErrOrgMemberLimitTooLow  = errors.New("member limit cannot be lower than current member count")
)

// organizationService implements OrganizationService.
//
// Plan 3 of #1303: a "member" of an org is a tenant, identified by
// (org_id, tenant_id). The user_id of the requester is recorded only as
// the representative for UI/audit; permission decisions ride on the
// tenant's role inside the org.
type organizationService struct {
	orgRepo        interfaces.OrganizationRepository
	userRepo       interfaces.UserRepository
	shareRepo      interfaces.KBShareRepository
	agentShareRepo interfaces.AgentShareRepository

View on GitHub (pinned to 988cbb0330)

Solutions

  1. Join the tenant to the organization (accept invite) before org-scoped operations
  2. Verify the tenant/org ids; membership may have been revoked
Defensive patterns

Strategy: type-guard

When it happens

Trigger: Thrown at internal/application/service/organization.go:32 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of Tencent/WeKnora@988cbb0330 (2026-09-02). Data as JSON: /api/errors/df9f0273d7a8efb0. Report an issue: GitHub.