user_id and role. Updating a membership changes its role.
Session authorization distinguishes read access from mutations. Organization owners and administrators can perform write operations; ordinary members are restricted from organization-scoped writes.