User Invitations
Categories:
The invitation system gives you precise control over how members join your organization, allowing you to streamline onboarding and enhance security.
You can create highly customized invitations for any scenario, from onboarding specific individuals to launching large-scale community challenges. Each invitation can be configured with expiration dates, usage quotas, and pre-assigned roles, ensuring new members get the right access from the moment they join.
Required permission
Managing invitations requires the Manage Invitations permission within your organization. Contact your organization administrator if you need access.Default organization state π
By default, organizations are closed: there is no open registration. A user cannot join your organization simply by navigating to a URL β they must either click a valid invitation link or register through a page associated with an organization that has a default invitation configured.
When no default invitation is set, new users who arrive at your organization’s registration page are registered as platform users but are not automatically added to your organization. They will have no organization membership and no roles until an administrator adds them or they accept an invitation link.
Two ways to designate the open signup invitation
An organization’s open signup invitation can be set in two places: the invitation picker in Edit Organization, or the isDefault setting on the invitation itself.
The Edit Organization selection takes precedence. The isDefault marker is used when no selection has been made there, or when the invitation that selection points at no longer exists.
Roles are not assigned automatically
When a user joins an organization via invitation, they receive only the roles explicitly listed on that invitation. If the invitation has no roles configured, the user joins with no role. Use theroles field on each invitation to ensure new members receive the correct initial permissions.Key capabilities π
The invitation system provides three main areas of control to help you manage access effectively.
Create custom invitations for any audience π
Tailor each invitation to your specific needs with three flexible modes:
- Precise invitation: Target a single user by specifying their full email address.
- Domain-wide invitation: Onboard an entire organization at once by allowing any email from a specific domain (e.g.,
@layer5.io). - Public invitation: Leave the email field blank to create an open link for public events (e.g., Academy Challenge invitations).
Use domain wildcards carefully
Patterns like@company.com allow anyone with that domain. Verify ownership and pair with roles and teams that grant only necessary access.Control the invitation lifecycle π
Manage access with settings that put you in control:
- Expiration date: Set a specific date and time after which the invitation link can no longer be used to join. This prevents new signups but does not affect members who have already accepted the invitation.
- Usage quota: Limit the number of times an invitation can be used. The invitations table shows current acceptance count alongside the limit (e.g.,
2 / 5).
Blank means unlimited
IfexpiresAt is not set, the invitation never expires. If quota is not set, the invitation has unlimited uses.Manage invitations dynamically π
Instantly revoke access by switching an invitation’s status between enabled and disabled at any time. A disabled invitation can be re-enabled later without recreating it.
How to create an invitation π
To create a new invitation, navigate to the Invitations page from the main menu. Click the Create New Invitation button to open the creation dialog.

Email notifications
After an invitation is created, a notification email is sent only to addresses listed in theemails field that are exact email addresses. Domain-wide patterns (e.g., @layer5.io) and public invitations (empty emails field) do not trigger individual notification emails β share the invitation link directly in those cases.
Invitation properties explained π
| Property | Description |
|---|---|
emails | List of email addresses or domain patterns allowed to use the invitation. Exact addresses (e.g., [email protected]) and domain patterns (e.g., @example.com) are both supported. If empty, the invitation is public. |
roles | List of roles automatically assigned to new members upon accepting the invitation. If empty, the user joins with no role. |
teams | List of teams new members are automatically added to upon accepting the invitation. |
quota | Number that limits how many users can accept the invitation. If not set, there is no usage limit. |
expiresAt | Date after which the invitation link can no longer be used. Does not affect existing members. If not set, the invitation never expires. |
status | Invitation status: enabled = active and usable; disabled = inactive (can be re-enabled later). |
name | A human-readable name used to identify the invitation. |
description | Additional information about the invitation’s purpose, for internal reference. |
isDefault | When enabled, marks this invitation as the organization’s open signup invitation. Users who register through your organization’s registration page are automatically enrolled through this invitation, receiving the pre-configured roles and teams. Without a default invitation, the registration page does not automatically add users to the organization. Only one invitation can be designated as the default at a time β designating a new one clears the previous. Turning this setting on or off requires the Manage Invitations permission; editing any other property of an invitation does not, and leaves the setting as it was. |
Managing existing invitations π
All existing invitations are displayed in a table showing key details for each invitation: its name and description, a copyable acceptance link, the owner, expiration date, quota usage, assigned roles and teams, and current status.

You can filter the list using the filter control at the top right of the table. Available filters are:
- Status β show only enabled or disabled invitations
- Roles β show invitations that grant a specific role
- Teams β show invitations that add members to a specific team
From the table you can perform the following management actions on each invitation:
- Copy Link: Click the copy icon next to the invitation URL to copy it for sharing.
- Edit Invitation: Click the pencil icon to open the edit dialog and modify any invitation properties.
- Delete Invitation: Click the trash icon to permanently remove the invitation. This action cannot be undone.
If another administrator deletes an invitation while your edit dialog is open, saving reports that the invitation was not found rather than reporting success. Close the dialog and reload the invitations table to see the current list. Whenever an edit cannot be saved, the dialog reports the specific reason it was refused.
Tracking who has accepted an invitation π
The Quota column in the invitations table always shows the number of users who have accepted an invitation alongside the configured limit β for example, 2 / 5 if a quota is set, or 2 / Unlimited if no quota is configured. This lets you monitor uptake at a glance.
To see the individual users who are now members of the organization, navigate to the User Management page. Members who joined via invitation appear there alongside their assigned roles.
What happens when a user accepts an invitation π
When a user clicks an acceptance link and is logged in, the system performs the following steps in order:
- Validates the invitation β confirms it exists, is
enabled, has not passed its expiration date, and has not exceeded its quota. - Checks email eligibility β verifies the user’s email matches the invitation’s
emailslist. An empty list allows any email (public invitation). - Adds the user to the organization β the user immediately becomes a member of the organization that owns the invitation.
- Assigns roles β all roles configured on the invitation are assigned to the user in that organization. If no roles are configured, the user joins with no role.
- Adds the user to teams β the user is added to all teams configured on the invitation.
Role and team assignment failures are non-blocking: the user is still added to the organization even if an individual role or team assignment fails.
How the open signup invitation is applied at sign-in π
The open signup invitation is not limited to first-time registration. It is applied whenever someone signs in through your organization’s own address, such as its custom domain, on every sign-in method that address offers, including email and password as well as social sign-in. Someone who already has a Layer5 Cloud account and has never been a member of your organization becomes a member on that sign-in, with the roles and teams the invitation configures.
It is applied only to people who are not already members, which has two consequences worth knowing:
- Roles and teams are never re-applied to an existing member. If you remove a role or a team from someone who joined this way, signing in again does not restore it.
- Each person is counted once. Repeated sign-ins by the same person do not increase the invitation’s acceptance count or add them to the organization a second time.
When open signup adds nobody
A person can sign in successfully and still not join your organization. The open signup invitation is applied only when all of the following hold:
- Its status is
enabled. - Its expiration date has not passed.
- Its quota has not been reached.
- The person’s email address matches its
emailslist. An empty list matches everyone.
When one of them does not hold, someone who is not already a member signs in as a platform user with no membership and no roles in your organization, and no error is shown to them. Existing members are unaffected: they keep the membership, roles, and teams they already have. Check these four properties first when people who sign in at your organization’s address are not appearing under User Management.
Use cases and examples π
The invitation system offers flexible configurations to fit a variety of use cases.
How invitation links handle unauthenticated users
When a user who is not logged in clicks an invitation link, the system saves the invitation ID in a short-lived 30-minute cookie and redirects them to the organization’s registration page. After a successful login or signup, the system reads the cookie and automatically completes the invitation acceptance, adding the user to the organization with the configured roles and teams.Scenario 1: Inviting a single team member π
- Goal: Provide a new employee with a secure, single-use invitation that grants the correct initial permissions.
- Configuration:
- Email: Set to the new member’s specific email address.
- Roles: Assign their specific role (e.g.,
Developer). - Teams: Add them directly to their project team (e.g.,
Frontend-Team). - Quota: Set to
1to ensure the link is only used once.
Scenario 2: Opening registration for an entire organization π
- Goal: Allow all employees from your company to join using their corporate email without individual invitations.
- Configuration:
- Email: Use a domain pattern to cover all employees (e.g.,
@yourcompany.com). - Roles: Assign a default role for all new members.
- Email: Use a domain pattern to cover all employees (e.g.,
Scenario 3: Launching a community challenge π
- Goal: Create a public signup link for a limited-time community event with a maximum number of participants.
- Configuration:
- Email: Leave blank for public access.
- Name: Give it a clear name like “Layer5 Challenge 2025”.
- Expiration date: Set to the date and time the challenge registration closes.
- Quota: Set to the maximum number of participants (e.g.,
100). - Roles: Assign a temporary role like
Learner.
Managing learner costs
The available seats for learners are determined by your organization’s subscription plan. Please be mindful of your subscription to manage costs effectively.Scenario 4: Granting temporary partner access π
- Goal: Give an external partner secure access to specific resources only for the duration of a project.
- Configuration:
- Email: Use the partner’s domain (e.g.,
@partner.com). - Teams: Add them only to a shared project team (e.g.,
Project-X-Shared). - Expiration date: Set to the project’s end date to prevent new signups after the project concludes.
- Description: Add a note for internal reference, such as “Temporary access for Project X contractors”.
- Email: Use the partner’s domain (e.g.,