DocumentationUsers, invites, and roles
Docs/Users, invites, and roles

Users, invitations, and roles

Open Users & Roles to manage organization membership. Owner and administrator permissions are required for changes; ordinary members see only the permitted read-only state.

Users and roles roster with active, unverified, and deactivated fixtures

  1. Select Invite user.
  2. Enter Email address.
  3. Choose Role: owner, admin, or member.
  4. Select Create invite.

Invite-user form

Role guidance:

  • owner — organization settings, destructive lifecycle, and full delegated authority;
  • admin — day-to-day user/network/security administration without every owner-only operation; and
  • member — normal user/device access.

Start with member unless the person has an explicit operating responsibility.

When SMTP is configured, Tunnex sends the invitation. When email delivery is off, the result shows a one-time Invitation link. Copy it immediately and send it through an authenticated private channel.

The link is a bearer credential. Do not paste it into chat rooms, screenshots, documentation, or tickets. Resending an invitation invalidates the old token.

The recipient opens the invitation URL and sees Accept your invitation:

  1. Enter Your name.
  2. Enter a password of at least 12 characters.
  3. Select Accept invitation.
  4. On You’re in, select Go to sign in.

Acceptance creates or attaches the account and membership; it does not automatically sign the recipient in.

Expand Invitation history and filter the list. Relevant states are:

StateMeaningAvailable action
PendingToken can still be acceptedResend or revoke
ExpiredTime window elapsedResend or revoke
AcceptedMembership was createdManage the member row
RevokedToken was withdrawn or supersededNo reuse

Errors such as invite_pending, invite_not_pending, invalid_role, and account_deactivated are server decisions. Refresh the roster before retrying an action after another administrator changed it.

Use the role selector on the member row. Before reducing an owner to admin or member, verify another active owner can sign in.

Deactivate an account when the person should no longer sign in. Deactivation is different from device revocation:

  1. Deactivate the user.
  2. Revoke their active devices if network access must stop immediately.
  3. Remove or replace rules that grant the person or their manual groups access.
  4. Review directory-sync health when membership is directory-managed.

Use Reactivate only after confirming the identity and role. A deactivated source can remain visible in a policy rule for auditability even though it matches no usable user session.

Use Reset 2FA on the member row only after independently verifying the person. Resetting MFA does not reset their password and does not revoke every existing device. Follow your incident procedure when compromise is suspected.

  • The roster shows the expected role and state.
  • A new recipient can sign in and sees the correct organization.
  • The audit log contains the invitation or membership action.
  • Access rules use the intended person/group, not a similarly named fixture.

Continue with MFA and account recovery before delegating administrative roles.

Documentation

Search Tunnex docs