Documentation Get help

Invite people and manage their access

Add people to Flowstate, change what they can see, and get someone back in after they lose their phone or passkey. First time setting up? Start with Sign-in and access.

You need to be a Flowstate admin.

Find people

Go to Organisation → People & roles → Users. If your organisation doesn’t use Organisation yet, go to Settings → Users & Access → Users. People are split into three tabs:

TabWho’s in it
ActivePeople who can sign in
PendingPeople you’ve invited who haven’t signed in yet
SuspendedPeople you’ve stopped from signing in

If Flowstate added someone because it found them in one of your connected AI providers, their name has “Found in provider on date” under it: the first provider it found them in, and when. People Flowstate found aren’t listed here until you invite them or they sign in. You’ll find them on People in Flowstate Helm; to invite one, follow Invite someone. See Find anyone and move them between teams.

Invite someone

  1. Go to Organisation → People & roles → Users and select Invite User.
  2. Enter their Email, and their Name if you like.
  3. Choose a Role, or leave No Role (use default).
  4. Select Send Invitation.

They appear under Pending, then move to Active the first time they sign in. From the menu on their row you can Resend Invitation or Revoke Invitation.

If Flowstate has already found the person in one of your AI providers, entering their email invites that same person, so you don’t end up with two.

Not sure which role to choose? See Roles and permissions.

Invite someone again

When you revoke an invitation, the person moves to Suspended. If they never signed in, you can invite them again:

  1. Go to Organisation → People & roles → Users and select Invite User.
  2. Enter the same Email, and choose the Role they should have now.
  3. Select Send Invitation.

They move back to Pending. Someone who signed in and was then suspended can’t be invited again. Select Reactivate User on their row instead.

Change someone’s name, email or role

  1. Open the menu on their row and select Edit User.
  2. Change their Name, Email or Role.

If your identity provider sets roles from groups, change the person’s group there instead. Otherwise their role changes back the next time they sign in or their groups change.

Reset someone’s second factor

Do this when someone has lost the phone or passkey they sign in with.

  1. Open the menu on their row and select Reset MFA.
  2. Confirm.

All their passkeys and authenticator apps are removed. Next time they sign in, Flowstate emails them a link and asks them to set up a second factor again. Before you reset, make sure you’re talking to the right person.

Suspend or reactivate someone

  • Select Suspend User on their row to stop them signing in. They move to Suspended.
  • Select Reactivate User on a suspended person to let them sign in again.

If you use SCIM, remove the person from their groups in your identity provider instead. See Provision accounts with SCIM.

See who invited or changed someone

When an admin invites someone, changes their name or role, or suspends or reactivates them, the activity log records it, with who did it.

  1. Go to Organisation → Sign-in & security → Activity log. If your organisation doesn’t use Organisation yet, go to Settings → Organisation → Activity Log.
  2. Open Entity type and choose Person.
  3. Read across each row for who made the change and what it was. A role change names both roles.

For the other filters and columns, see Review the activity log.

Create your own role

  1. Go to Organisation → People & roles → Roles. If your organisation doesn’t use Organisation yet, go to Settings → Users & Access → Roles.
  2. Select Create Role. Or, to start from a role that’s close to what you need, open its menu and select Duplicate Role.
  3. Enter a Name and Description.
  4. Choose a Dashboard View Mode.
  5. Tick the Permissions.
  6. Select Create.

Built-in roles have a System badge and can’t be deleted. To remove a role you made, move people off it, then select Delete Role from its menu.

Change a role’s permissions

  1. Go to Organisation → People & roles → Roles.
  2. Open the menu on the role’s row and select Edit Role.
  3. Tick or untick Permissions. You can also change the Name, Description and Dashboard View Mode.
  4. Select Update.

The change applies to everyone with that role. Permissions your own role doesn’t have are greyed out and marked “(You don’t have this permission)”.

Choose what new people get when they join

This decides what happens when someone signs in for the first time without an invitation.

  1. Go to Organisation → People & roles → User enrolment. If your organisation doesn’t use Organisation yet, go to Settings → Organisation → User Enrollment.
  2. Turn Automatically enroll new users on or off. When it’s on, anyone allowed to sign in gets an account the first time they do.
  3. Choose a Default Role for those people. The list runs from least access to most.
  4. Select Save Enrollment Settings.

With automatic enrolment off, only people you invite, or people your identity provider adds, can get in.

Someone Flowstate added when it read a provider’s people, or an admin created on Users & teams, already has the AI Viewer role and keeps it when they sign in, unless your identity provider sets roles from groups, which it re-applies each time they sign in (see Change someone’s name, email or role). Anyone else who signs in without an invitation gets the Default Role, whatever role that is, so if you’ve set AI Viewer as the Default Role, that’s what they get.

If something’s not right

Invite User isn’t shown. Your role doesn’t include Invite Users. Update Roles doesn’t let someone invite on its own. Ask an admin to add Invite Users to your role, or to send the invitation.

“Cannot invite with this role: it contains permissions you do not have”. The role includes permissions your own role doesn’t have. Choose a smaller role, or ask someone with more access to send the invitation.

“User with this email already exists in this organization”. They already have an account here. Look under Active, Pending and Suspended. Select Resend Invitation for someone under Pending. To invite someone you revoked before they signed in, see Invite someone again. Anyone else under Suspended needs Reactivate User.

“Cannot grant permissions you do not have: …” when you select Update. The role has permissions your own role doesn’t have, so you can’t save changes to it. Ask someone with more access to edit it.

Someone sees “You are not authorised to access this organisation.” Automatically enroll new users is off and they haven’t been invited. Invite them.

Reset MFA isn’t in the menu. The person hasn’t set up a second factor yet, or they’re still under Pending.

A role you changed keeps changing back. Their role comes from your identity provider. Move them to a different group there.

A manager can see the pay in another team’s budget. Anyone asked to approve a team’s budget can see the pay in the changes they review, whatever their role. That includes the manager of the team above and anyone your organisation names as a budget approver. To stop it, change who approves that team’s budget. See Choose who approves budgets.

Someone selects Approve on a budget and sees “Forbidden: You do not have the required permission”. Their role doesn’t have Approve Budget Proposals. Add it to their role, or ask another approver to approve it.

Someone selects Approve on a week of effort and sees “Failed to approve — please try again.” Check their role has Approve Effort. Being listed as an approver in Settings → Scenarios → Review Workflow isn’t enough on its own. See Approve or send back a week.