Read one company user
Returns one visible membership with local display name, immutable login email, roles, status, last login and lockVersion. Company permission: `getCompanyUser`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
id*stringuuidCompany membership detail
*/*- response
contactEmail?stringdisplayName?stringemail?stringid?stringuuidlastLogin?stringdate-timelockVersion?integerint32roles?array<string>status?stringuserId?stringuuidcurl -X GET 'https://api.monetaryai.uz/api/v1/settings/users/497f6eca-6276-4993-bfeb-53cbbbba6f08'{ "contactEmail": "string", "displayName": "string", "email": "string", "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "lastLogin": "2019-08-24T14:15:22Z", "lockVersion": 0, "roles": [ "string" ], "status": "string", "userId": "2c4a230c-5085-4924-a3e1-25fb4fc5965b"}List company users for the settings table GET
Bounded page with company display name, immutable login email, role codes, ACTIVE/SUSPENDED status, last login and lockVersion. ENDED memberships are hidden but retained for audit. Search matches literal name/email substrings; role and status filters are optional. Add a user through the recipient-bound invitation API, never by setting another person's password. Company permission: `listCompanyUsers`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.
Restore a role's default access POST
Versioned reset to documented defaults; custom changes in other companies are untouched. Company permission: `resetCompanyRolePermissions`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.