Invite people to join your organization, then manage each person’s roles and department access. The person’s FTE Tree account remains their own; organization administrators manage only their access to that organization.

Give every person an individual account so approvals, comments, imports, and activity remain attributable.

Before you begin

You need the Manage user access permission. You can grant only permissions and departments that you are authorized to grant. Invitation and membership changes require an MFA check within the previous 24 hours in the current session.

Before inviting someone

Confirm:

  • The person’s exact email address.
  • The person’s name and optional job title as they should appear in this organization.
  • Whether the organization’s email policy allows that domain.
  • The roles needed for the person’s responsibilities.
  • All departments or the specific departments the person needs.
  • Whether company sign-in is required.
  • Whether the organization requires an authenticator app for standard access and whether the person can use a compatible app.
  • Whether the invitation should start immediately or on a scheduled date.

A blank department selection grants no department access. It never means all departments.

If company sign-in is required, every invited person must be able to use that exact service. A guest, contractor, emergency account, or other person outside the service cannot enter by using an authenticator app instead. Add the person to the company service before requiring it, or use an approved organization access plan that does not require that service. Provider MFA and FTE Tree MFA remain separate.

Send an invitation

  1. Open the invitation list.
  2. Select Invite user.
  3. Enter the person’s name, optional job title, and email address.
  4. Choose one or more access roles.
  5. Choose department access when the role requires it.
  6. Set availability dates when needed.
  7. Review the summary.
  8. Submit and complete MFA if prompted.

Choose Invite without access roles only when the person should join before responsibilities are known. After acceptance, areas that require an access role remain unavailable until someone who can manage user access assigns one.

Review invitation status

An invitation can be:

  • Scheduled.
  • Active.
  • Expired.
  • Cancelled.
  • Accepted.
  • Blocked by a changed role or policy.

Use Send reminder for an active invitation. Update the invitation when its roles or dates should change. Cancel it when it should no longer be accepted; cancellation preserves history.

If the address is wrong, cancel the invitation and send a new one. The recipient must accept with the same verified email.

What happens on acceptance

The job title, selected roles, and departments become part of the membership when the recipient accepts, so their first organization visit has the intended identity and access. A job title helps distinguish people in user and approval lists; it does not grant access.

Acceptance is blocked when a selected role is no longer available or the verified email no longer meets the current policy. Update the invitation rather than asking the recipient to work around the check.

If company sign-in is required, invitation acceptance does not bypass it.

Manage an existing user

Open the user list and select the membership to:

  • Review the roles and departments that currently provide access.
  • Add or remove role assignments.
  • Review membership activity and history.
  • Update the optional job title shown with the person’s name in this organization.
  • Update organization notification settings where applicable.
  • Deactivate organization access.

Access changes take effect when the person next opens a page or takes an action.

Deactivate organization access

Use Deactivate user access when the person should no longer enter this organization.

Deactivation:

  • Ends the active membership and role assignments.
  • Keeps approvals, comments, messages, imports, and activity in history.
  • Does not deactivate the person’s FTE Tree account.
  • Does not affect other organizations.
  • Allows the person to be invited again later.

You cannot deactivate your own organization access from this page, and FTE Tree protects the administrative access needed to keep an organization manageable.

Do not rename or reuse an old account for a new person.

Review user access

Run the Access Review report:

  • After inviting a group of users.
  • After changing the department hierarchy.
  • After changing compensation, security, billing, or user access.
  • Before a formal access review.

The report keeps name, job title, and email in separate columns so reviewers can identify people without treating the title as an access role.

A No department access entry grants no department access. Correct it by selecting specific departments or All departments.

Keep administrative access available

The organization creator receives the standard organization administrator role with access to all departments, rather than permanent owner status. Before removing an administrator, give the needed responsibilities to another active person. FTE Tree protects the critical access needed to continue managing access and security. Contact support if no remaining administrator can make the required change.