Skip to main content
There is no public sign-up. Every account in a workspace arrives by invitation from someone who already holds one, and the first owner account is bootstrapped when the workspace is provisioned.
Sending invitations needs the invitations.send permission; cancelling one needs invitations.revoke. Both are held by Admin and Owner by default, and can be granted to a custom role.

Sending an invitation

Invitations live on the Access management page, not in Settings.
1

Open Access management, People

Navigate to Access management → People → Invite. The dialog walks three stages: Who, Access, Review.
2

Who

Enter one or more work email addresses. Each becomes its own invitation, so you can bring in a whole team in one pass. Addresses the work-email policy rejects are flagged here with the reason, before you send anything.
3

Access

Pick the roles they will hold. Only roles you are permitted to hand out are offered, and the dialog shows the effective permissions the selection grants.
4

Review

Confirm the addresses, the roles, and the seats it will consume, then send.

Seats

The dialog counts seats used plus invitations still outstanding against your license limit, and refuses to send an invitation that would put you over. Pending invitations hold a seat because accepting one is unilateral: the invitee decides when, and the seat has to be there when they do. If your license sets no seat limit, no meter is shown.

Roles you can assign

Two guardrails apply on top of your own permissions:
  • Only an owner can invite an owner.
  • You cannot invite someone into a role you could not grant an existing user. Without this, a role holding invitations.send plus users.reset_password could invite an admin, reset that account’s password, and sign in as it.
An invitation naming a role your workspace does not define is refused outright rather than quietly granting nothing.

Which addresses are accepted

An account is expected to live at an organization’s own mail domain, so invitations are refused for: A blocked domain blocks everything beneath it, so mail.gmail.com is refused too.
If a customer genuinely uses a domain this policy misreads, it can be allowlisted per deployment without a release. Ask your account manager rather than working around it.
This policy governs the paths where an address enters the system. It is never applied to sign-in or password reset, so tightening it can never lock out an account that already exists.

What the invitee receives

An email titled “You’re invited to Blindsight”, naming who invited them and the role they are being given, with an Accept invite button. If your workspace requires two-factor authentication, the email says so up front. What happens on their side is covered in Accepting an invite. The short version: they set a password, then sign in. Accepting does not sign them in by itself.

The workforce variant

Rolling out endpoint DLP or Shadow AI to people who do not otherwise use the console has its own invitation, which carries the desktop agent download and install steps in the same email, so one message covers account setup and device setup. Anyone who already has a workspace account gets an install-only message instead, with no invitation link, since there is no account to create. See Install the agent and Fleet rollout for the MDM path, which needs no per-user invitation at all.
The window is configurable per invitation, from 1 hour to 30 days, and the deployment-wide default can be changed. An expired link tells the invitee it expired and to ask for a new one.
Sending a fresh invitation to an address with one already open revokes the old one. Exactly one link per address is redeemable at any moment, which is also how you correct a mis-sent invitation: send another.
The moment one link is redeemed, every other outstanding invitation for that address is revoked, so a second token cannot sit redeemable for the rest of its window.
Revoke kills the token now and records the invitation as cancelled by an admin, distinct from one that simply lapsed. You cannot revoke an invitation that has already been accepted; deactivate the user instead.

When an invitation is refused

Every invitation sent, cancelled, and accepted is recorded in the audit trail with the actor, the target address, and the roles granted.

Next

Accepting an invite

What your teammates see, step by step, through their first sign-in.

Access management

Built-in roles, custom roles, the permission catalog, and per-resource access.