Skip to main content
Team & Access

Inviting teammates: the invite lifecycle from email to first sign-in

The Team page is where you bring coworkers into your StackJack account. An invite creates their sign-in identity, emails them setup instructions, and — the moment they first sign in — turns into an…

Written By Christopher Scaminaci

Last updated About 22 hours ago

The Team page is where you bring coworkers into your StackJack account. An invite creates their sign-in identity, emails them setup instructions, and — the moment they first sign in — turns into an active team membership with the tools you chose. There is no separate "accept invite" screen.

An invite is one of three ways someone joins. They can also sign in on their own and wait for you to approve them (Approving self-registered members), or Directory sync can provision them straight from a Microsoft Entra group — active immediately, with their roles already assigned, and with no invitation, no invite email, and no pending state.

Before you start

  • You need the Owner, Co-owner, or Administrator role (see Team roles).
  • Your account needs at least one active connector subscription. If you have none, the Team page shows a "Subscription Required" card that links you to the Connectors page first.

Send an invite

  1. In the left sidebar, select Team.

  2. In the Invite a Team Member card, enter the teammate's Email, First Name, and Last Name.

  3. (Optional) Expand Microsoft sign-in (optional) and paste the person's Microsoft Entra object ID. StackJack links it to their new account so Sign in with Microsoft works for them from the very first login. Leave it blank and they sign in with a password instead.

  4. (Optional) Pick any Roles (optional) chips — see Assigning roles at invite time below.

  5. (Optional) Expand Extra tools (optional) to pick individual connector tools on top of whatever their roles cover. The summary beside the heading tells you what will be saved:

    SummaryWhat you get
    All tools (no roles picked, picker untouched)A snapshot of every connector tool your plans include today, not a standing grant
    none — tools come from the selected roles (roles picked, picker untouched)Nothing extra; the roles are the whole grant
    N tools selectedExactly what you picked

    A snapshot does not grow. Tools from a connector you add later need an edit. For a grant that keeps up with the catalog, use a custom tool role instead — a role's rules are catalog-wide.

    StackJack's own support, status, and documentation tools are always available and are not part of this selection. The automation tools are offered here and do need granting.

  6. Select Send Invite.

The current Team page invite card with email and name fields, the optional Tool Permissions summary, and Send Invite
The bounded invite card uses the Portal's example placeholders and shows the current catalog count in the collapsed optional-permissions summary.

What happens behind the scenes:

  • A sign-in identity is created for that email inside your organization.
  • A password-setup email is sent so they can choose a password (this email comes from the identity service, so it may arrive from a zitadel.cloud address).
  • A StackJack invite email is sent letting them know they've been added.
  • A pending invite appears in the Pending Invites list.

If the setup email could not be sent, the portal tells you immediately — the invite still works, and your teammate can use Forgot password on the sign-in page as a full substitute for the setup email.

Assigning roles at invite time

If your account has at least one custom tool role, the invite card shows a Roles (optional) row of chips — click to toggle. The chips appear even when none of your connectors is currently connected, because a role's rules are catalog-wide: you can assign one ahead of the credential it will eventually cover. The card states the rule itself: "The invited member gets every tool their roles cover, plus any extras picked below. Roles are added: if this address already has a pending invitation, the roles it already holds are kept. Use Edit Roles on the pending invitation to remove one."

Two things worth knowing:

  • With roles picked and the extras picker left untouched, the invitation ships with no extras at all — the person arrives holding exactly their roles' tools. If you deliberately change the extras selection, that exact set is kept alongside the roles.
  • Roles are assigned right after the invitation is created. If it fails you get an "Invited — Roles Not Assigned" warning: the invitation itself was sent, so fix it with Edit Roles on the pending row rather than re-inviting. If the warning instead says the roles were assigned and a follow-up check failed, do the opposite — don't re-assign, just reload the page.

What your teammate does

  1. They open the password-setup email and choose a password.
  2. They go to the portal and sign in. If they use a StackJack password, MFA enrollment is required on first sign-in; if they sign in with Microsoft, your identity provider's own MFA policy applies — see Sign-in, MFA, and sessions.
  3. That's it. The invite is accepted automatically at first sign-in — their membership activates with the tools you assigned, and the invite disappears from Pending Invites.

Each invite is tied to the specific identity that was created for that email address, so it cannot be consumed by a different account that happens to use the same address.

Invite expiry, revoking, and resending

SituationWhat to do
Invite still pending, not yet expiredNothing — the invitee just needs to sign in. Sending the invite again reuses that same pending invitation: it updates the extra-tool selection and adds any newly-picked roles, but it never removes a role (use Edit Roles on the pending row for that) and it does not extend the 7-day expiry. Changes apply at their next sign-in.
Invite expired (invites last 7 days)Send a new invite from the Team page. There is no separate "extend" button. An expired invite stays in Pending Invites with an Expired badge and Resend greyed out, because Resend keeps the old expiry; revoke it once the new one is accepted. If the person signs in on the expired invite, they see an Invitation Expired notice naming your organization.
Invitee never got the password-setup emailIn Pending Invites, select Resend on their row — it re-sends both emails (the credential email arrives with the subject Reset password). If Resend is greyed out on a row marked Expired, send a new invite instead. If it is greyed out on a row still marked Pending, the invite predates resend support: Revoke it and send a new invite. Forgot password on the sign-in page also works. (The Unlinked Identity Users card's Resend Setup Email applies only to identities with no pending invite — for example after an invite was revoked, or a user created directly in the identity portal.)
You want to cancel an inviteIn Pending Invites, select Revoke and confirm.

Troubleshooting invites

  • "Domain not verified" banner on the Team page. If your email domain hasn't been verified with the identity service yet, automatic sign-in routing for your domain is inactive. Invitees should always use the link in their invite/setup email rather than navigating to the sign-in page cold.

  • The invitee already has an account elsewhere. Sign-in identities are unique across all of StackJack. If the person's email already exists in another organization, StackJack usually resolves this automatically; if the invite fails with an error asking you to contact support or mentioning reconciliation, that refusal is deliberate — email support@stackjack.io and the StackJack team will relocate the identity safely.

  • The invitee signed in before the invite existed (for example, they connected an AI assistant on their own first). They appear on your Team page as a pending, self-registered member rather than as an accepted invitee. You have two ways forward, and both work:

    • Approve them directly. On their Team row, use Edit Roles or Edit Tools to grant access. This is immediate and does not wait on the invite. See Approving self-registered members.
    • Let the invite apply on their next sign-in. A pending, unexpired invite whose email matches theirs is applied the next time they sign in: it grants the tools it carried and transfers the roles you picked on it. You do not have to revoke it and start over.

    Matching is by email address, so the invite must carry the same address the person actually signs in with. If they signed in with a different address — a personal one, or an alias — no invite matches, and approving them directly is the way through. Watch for that specifically when someone's sign-in identity does not match the address you invited: see Access troubleshooting.

Adding someone who already has a sign-in identity

If a person already exists in your organization's identity directory but isn't on your StackJack team (they show up in the Unlinked Identity Users card), you don't need an email invite: select Add to Team, optionally scope their tools, and they become a member immediately.