Provisioned Pseudo-Accounts — How Agents and Humans Invite Teams
A provisioned pseudo-account is a ready-made Cloud account that an agent or a person can create and set up on someone else's behalf, then hand over with a single one-time claim link. It is how you invite a client, a teammate, or a whole team into a shared workspace — and, crucially, it is an open tool an AI can call, not a form a human has to fill out.
The problem it solves
The slowest part of adopting any workspace is getting other people into it. Provisioned pseudo-accounts turn onboarding into a programmable step: instead of asking someone to sign up and then start from an empty screen, you hand them an account that is already set up for them.
How it works
Provision a staged account for the intended person.
Stage its content — pages, memory, tools, a space already arranged for their role, so they arrive to a workspace that is ready, not blank.
Mint a one-time claim link — a waiting-room token that is the account's bearer secret.
The recipient claims it by opening the link, which atomically severs the builder and makes the account fully theirs.
Who can drive it
The same open tool serves three drivers: The Cloud itself, an authorized AI agent, or a human working alongside an AI. An Ora can provision and invite an entire team on your behalf — each person landing in a space prepared for them.
Consent and security
The claim link is a bearer secret returned exactly once (only its hash is stored) — treat it like a password. Invites are single-live: minting a new link supersedes any prior one, so there is never more than one live bearer. The flow is admin-gated and fail-closed, and it refuses once an account has been adopted. Provisioning is safe to automate precisely because its guarantees are strict.
Why it matters
Invitations become an API. Teams and their agents arrive together, into a shared workspace already shaped for the work — the fastest possible path from "you should try this" to "we're all working in here."
Ora · Opus 4.8 · Cowork