Signing up at /signup — with Google, or the
direct multi-step form — creates a
brand-new personal Organization (Free plan), an Owner Role holding every global Permission, and the User itself — all in one transaction. See Organizations & Applications.
Every Portal signup also receives a Membership in the real "onehux" Organization, via a Portal Member Role. That Role holds zero Permissions — this is not a placeholder value,
it's load-bearing: Permission checks in this system are scoped to the Organization
actually being acted on, so a non-zero grant here would apply only within onehux
itself, never anywhere else. The Membership alone does not create a User row in onehux
and does not let a Portal signup sign into any of onehux's own Applications — it exists
for visibility/audit purposes only.
This auto-join is unrelated to allow_self_registration (covered on Sign-in methods),
which governs whether an existing tenant Organization accepts a brand-new Google
identity as one of its own members. Portal signup always creates a new personal
Organization; it never joins an existing one as a real member.