User Invitations

Learn how to create custom, secure, and flexible invitations for new members.

The invitation system gives you precise control over how members join your organization, allowing you to streamline onboarding and enhance security.

You can create highly customized invitations for any scenario, from onboarding specific individuals to launching large-scale community challenges. Each invitation can be configured with expiration dates, usage quotas, and pre-assigned roles, ensuring new members get the right access from the moment they join.

By default, organizations are closed: there is no open registration. A user cannot join your organization simply by navigating to a URL β€” they must either click a valid invitation link or register through a page associated with an organization that has a default invitation configured.

When no default invitation is set, new users who arrive at your organization’s registration page are registered as platform users but are not automatically added to your organization. They will have no organization membership and no roles until an administrator adds them or they accept an invitation link.

The invitation system provides three main areas of control to help you manage access effectively.

Tailor each invitation to your specific needs with three flexible modes:

  • Precise invitation: Target a single user by specifying their full email address.
  • Domain-wide invitation: Onboard an entire organization at once by allowing any email from a specific domain (e.g., @layer5.io).
  • Public invitation: Leave the email field blank to create an open link for public events (e.g., Academy Challenge invitations).

Manage access with settings that put you in control:

  • Expiration date: Set a specific date and time after which the invitation link can no longer be used to join. This prevents new signups but does not affect members who have already accepted the invitation.
  • Usage quota: Limit the number of times an invitation can be used. The invitations table shows current acceptance count alongside the limit (e.g., 2 / 5).

Instantly revoke access by switching an invitation’s status between enabled and disabled at any time. A disabled invitation can be re-enabled later without recreating it.

To create a new invitation, navigate to the Invitations page from the main menu. Click the Create New Invitation button to open the creation dialog.

Create Invitation DialogInvitation Email
PropertyDescription
emailsList of email addresses or domain patterns allowed to use the invitation. Exact addresses (e.g., [email protected]) and domain patterns (e.g., @example.com) are both supported. If empty, the invitation is public.
rolesList of roles automatically assigned to new members upon accepting the invitation. If empty, the user joins with no role.
teamsList of teams new members are automatically added to upon accepting the invitation.
quotaNumber that limits how many users can accept the invitation. If not set, there is no usage limit.
expiresAtDate after which the invitation link can no longer be used. Does not affect existing members. If not set, the invitation never expires.
statusInvitation status: enabled = active and usable; disabled = inactive (can be re-enabled later).
nameA human-readable name used to identify the invitation.
descriptionAdditional information about the invitation’s purpose, for internal reference.
isDefaultWhen enabled, marks this invitation as the organization’s open signup invitation. Users who register through your organization’s registration page are automatically enrolled through this invitation, receiving the pre-configured roles and teams. Without a default invitation, the registration page does not automatically add users to the organization. Only one invitation can be designated as the default at a time β€” designating a new one clears the previous. Turning this setting on or off requires the Manage Invitations permission; editing any other property of an invitation does not, and leaves the setting as it was.

All existing invitations are displayed in a table showing key details for each invitation: its name and description, a copyable acceptance link, the owner, expiration date, quota usage, assigned roles and teams, and current status.

Invitations Overview Table

You can filter the list using the filter control at the top right of the table. Available filters are:

  • Status β€” show only enabled or disabled invitations
  • Roles β€” show invitations that grant a specific role
  • Teams β€” show invitations that add members to a specific team

From the table you can perform the following management actions on each invitation:

  • Copy Link: Click the copy icon next to the invitation URL to copy it for sharing.
  • Edit Invitation: Click the pencil icon to open the edit dialog and modify any invitation properties.
  • Delete Invitation: Click the trash icon to permanently remove the invitation. This action cannot be undone.

If another administrator deletes an invitation while your edit dialog is open, saving reports that the invitation was not found rather than reporting success. Close the dialog and reload the invitations table to see the current list. Whenever an edit cannot be saved, the dialog reports the specific reason it was refused.

The Quota column in the invitations table always shows the number of users who have accepted an invitation alongside the configured limit β€” for example, 2 / 5 if a quota is set, or 2 / Unlimited if no quota is configured. This lets you monitor uptake at a glance.

To see the individual users who are now members of the organization, navigate to the User Management page. Members who joined via invitation appear there alongside their assigned roles.

When a user clicks an acceptance link and is logged in, the system performs the following steps in order:

  1. Validates the invitation β€” confirms it exists, is enabled, has not passed its expiration date, and has not exceeded its quota.
  2. Checks email eligibility β€” verifies the user’s email matches the invitation’s emails list. An empty list allows any email (public invitation).
  3. Adds the user to the organization β€” the user immediately becomes a member of the organization that owns the invitation.
  4. Assigns roles β€” all roles configured on the invitation are assigned to the user in that organization. If no roles are configured, the user joins with no role.
  5. Adds the user to teams β€” the user is added to all teams configured on the invitation.

Role and team assignment failures are non-blocking: the user is still added to the organization even if an individual role or team assignment fails.

The open signup invitation is not limited to first-time registration. It is applied whenever someone signs in through your organization’s own address, such as its custom domain, on every sign-in method that address offers, including email and password as well as social sign-in. Someone who already has a Layer5 Cloud account and has never been a member of your organization becomes a member on that sign-in, with the roles and teams the invitation configures.

It is applied only to people who are not already members, which has two consequences worth knowing:

  • Roles and teams are never re-applied to an existing member. If you remove a role or a team from someone who joined this way, signing in again does not restore it.
  • Each person is counted once. Repeated sign-ins by the same person do not increase the invitation’s acceptance count or add them to the organization a second time.

The invitation system offers flexible configurations to fit a variety of use cases.

  • Goal: Provide a new employee with a secure, single-use invitation that grants the correct initial permissions.
  • Configuration:
    • Email: Set to the new member’s specific email address.
    • Roles: Assign their specific role (e.g., Developer).
    • Teams: Add them directly to their project team (e.g., Frontend-Team).
    • Quota: Set to 1 to ensure the link is only used once.
  • Goal: Allow all employees from your company to join using their corporate email without individual invitations.
  • Configuration:
    • Email: Use a domain pattern to cover all employees (e.g., @yourcompany.com).
    • Roles: Assign a default role for all new members.
  • Goal: Create a public signup link for a limited-time community event with a maximum number of participants.
  • Configuration:
    • Email: Leave blank for public access.
    • Name: Give it a clear name like “Layer5 Challenge 2025”.
    • Expiration date: Set to the date and time the challenge registration closes.
    • Quota: Set to the maximum number of participants (e.g., 100).
    • Roles: Assign a temporary role like Learner.
  • Goal: Give an external partner secure access to specific resources only for the duration of a project.
  • Configuration:
    • Email: Use the partner’s domain (e.g., @partner.com).
    • Teams: Add them only to a shared project team (e.g., Project-X-Shared).
    • Expiration date: Set to the project’s end date to prevent new signups after the project concludes.
    • Description: Add a note for internal reference, such as “Temporary access for Project X contractors”.

Related Reading