Ensure the existing Organization model has guarded = [] and a membership relation matching the schema. The supplied spec uses members():

public function members() { return $this->belongsToMany(User::class, 'organization_user')->withPivot('role')->withTimestamps(); }

The registration controller calls members()->attach($user->id, ['role' => 'owner']). If your current relation is named differently, change the controller to match it.

If `organization_user.created_at` exists but `updated_at` does not, omit `withTimestamps()` or add the pivot updated_at column.

For production, add an `EnsureOrganizationApproved` middleware to every business route group. It should load the authenticated user's current organization and abort/redirect unless approval_status === 'approved'; exempt `/registration/pending`, logout, admin routes, and static/public pages. This protects sessions that were already open when a workspace is rejected.
