Archiving usually ships as a UI change. The workspace moves to an "Archived" tab, the edit buttons go grey, and everyone moves on.
The API often never hears about it. A script with an old token, a webhook handler, or a teammate with a bookmarked form can still create tasks, rename files, or invite people into a workspace that's supposed to be frozen. Billing tends to break the same way: a customer downgrades or stops paying, the screens lock, and writes keep landing.
What helps:
- Put the workspace state into the permission check itself. "Can this user edit tasks here?" should come back no when the workspace is archived, whatever role they hold.
- Keep reads working. People archive things so they can still look them up later.
- Decide what unarchiving needs. Usually that's an admin or owner action, and it should be checked and logged like any other role change.
- Cover background jobs. Imports, syncs, and scheduled automations that write into the workspace should check the same state before they run.
Quick test: archive a workspace, then send a create or update request straight to the API with a token that was valid before. You want a 403 with a clear reason. A 200 means the archive only exists in the UI.
Top comments (0)