Invite Members
Workspace membership is a prerequisite for using an app. After joining, the apps a member can use are determined by the view permissions assigned to groups for each app.
This page explains how to invite members, choose their roles, and manage invitations.
Invitation flow
Section titled “Invitation flow”- Open the workspace member management page in the console.
- Select Invite.
- Enter the users’ email addresses, up to 50 at a time.
- Select a role.
- Create the invitations.
An invitation link is valid for seven days from the time it is created. Keelson automatically emails each invited user a unique invitation link. When the user opens and accepts the link, they become a workspace member.
The invitation link also appears in the console. If the email cannot be delivered, share the corresponding link with the invited user directly.
Choosing a role
Section titled “Choosing a role”Select the role to assign to the member when you create the invitation.
| Role | Intended use | Developer seat |
|---|---|---|
| Owner | Administrator of the entire workspace | Used |
| Admin | Member and app administrator | Used |
| Developer | Builds and deploys apps | Used |
| App User | End user of deployed apps | Not used |
For details about each role, see Members & App Permissions.
Who can invite each role?
Section titled “Who can invite each role?”- Owners can invite members with any role, including Owner.
- Admins can invite Admins, Developers, and App Users, but cannot invite an Owner.
- Developers and App Users cannot invite members.
Developer seats
Section titled “Developer seats”Invitations for the Owner, Admin, and Developer roles consume developer seats under the workspace’s plan. An unaccepted invitation that has not expired reserves one developer seat as soon as it is created. The usage display counts reserved seats, including pending invitations that have not expired. When an invitation is accepted or a member’s role is changed, the limit check counts only members who have already accepted.
You cannot invite one of these roles when the developer-seat limit has been reached. App Users do not consume developer seats, so they can be invited regardless of that limit.
If no developer seats are available, consider upgrading the plan or changing an existing member who no longer needs a developer role to App User.
Invitation states
Section titled “Invitation states”An invitation has one of four states.
| State | Meaning |
|---|---|
| Pending | Created but not yet accepted |
| Accepted | Accepted; the user is now a member |
| Revoked | Revoked by an administrator |
| Expired | The invitation has expired |
You can check invitation states from the member management page in the console.
Revoking an invitation
Section titled “Revoking an invitation”An Owner or Admin can revoke an invitation while it is Pending. Its link stops working immediately after revocation.
Resending an invitation
Section titled “Resending an invitation”Only Pending invitations can be resent. Resending issues a new link and invalidates the old link. The new link is valid for seven days from the time it is resent.
If an invitation is expired or revoked, create a new invitation for the same email address.
Accepting an invitation
Section titled “Accepting an invitation”The invited user completes these steps:
- Open the invitation link received from the administrator.
- Sign in with a Google or Microsoft account.
- Accept the invitation.
- Join the workspace and use apps for which they have view permission.
Other ways to join
Section titled “Other ways to join”If domain auto-join is enabled for the workspace, users can join in these ways in addition to an invitation:
- Join URL — Opening the URL immediately adds the user as a member without waiting for approval.
- Discover — The user requests access from Discover and waits for an administrator to approve the request.
Both methods are available only when the user’s email domain is an allowed domain for the workspace. For a domain with an approval-based policy, join URLs and Discover requests are unavailable, so an administrator must invite the user.
For configuration details, see Members & App Permissions.
Troubleshooting invitations
Section titled “Troubleshooting invitations”An invitation cannot be sent
Section titled “An invitation cannot be sent”- Does the sender have permission to invite? Only Owners and Admins can send invitations.
- Is the email address correct? Check the entered address.
- Is the user already a member? Check the member list.
- Are enough developer seats available? When inviting an Owner, Admin, or Developer, check the plan’s seat limit.
The invitation email cannot be found
Section titled “The invitation email cannot be found”First check the spam folder. If the email is not there, ask the administrator who created the invitation to share the link displayed in the console.
An administrator can resend an invitation while it is Pending. Resending invalidates the old link.
The invitation cannot be accepted
Section titled “The invitation cannot be accepted”- Is the user signed in with the invited address? Another account cannot accept the invitation.
- Has the invitation expired? Create a new invitation after expiration.
- Was the invitation revoked? Ask an administrator to check its state.
The member cannot access an app after joining
Section titled “The member cannot access an app after joining”- Does the member have view permission for the app? Ask an administrator to check that app’s permissions.
- Is the member signed in with the correct account? Take care when switching between multiple accounts.
- Are IP restrictions blocking the request? Connect from an allowed network.
Frequently asked questions
Section titled “Frequently asked questions”Does an invitation grant access to every app?
Section titled “Does an invitation grant access to every app?”No. The user needs both workspace membership and view permission assigned to a group for each app. Members with manage permission for an app can change that app’s permission settings.
Do invitations expire?
Section titled “Do invitations expire?”Yes. An invitation expires seven days after creation. Create a new invitation if the original has expired.
Can I change a member’s role after inviting them?
Section titled “Can I change a member’s role after inviting them?”Yes. After the member joins, an Owner or Admin can change the role from the console.
Can I invite multiple people at once?
Section titled “Can I invite multiple people at once?”Yes. You can enter up to 50 email addresses in a single operation and invite them together.
Related pages
Section titled “Related pages”- Members & App Permissions — Role details and domain policies
- Auth & Login — Authentication and the login flow
- IP Allowlist — Restrict access by IP address