Kinds
The last exclusion is deliberate: the admin who just suspended someone does not need telling they
did it.
group.membership_changed is emitted once per permission change, from the before/after state of
PUT /groups/{id}/members/{userID}/permissions. That endpoint exists partly for this — reconciling
permissions in one call rather than several /grants calls avoids a burst of notifications for what
is really one decision.
Reading them
PATCH /notifications/{id} and {"read": true}, or clear the lot with
POST /notifications/read-all. Only true is accepted — there is no marking something unread.
Each notification carries an optional resource (kind and id) and action (label and href), so a
client can link straight to the thing needing attention.
RESEND_API_KEY and CUSTOS_EMAIL_FROM. Without them the control plane falls back to
logging, which is what makes development workable — see
Configuration.