- The invited or registered work email address
- The newest invitation or exact sign-in error without sharing the link or password
- The intended workspace name and an Owner/Admin contact
- Access to the email account used for verification or recovery
Identify the access stage
| Stage | Symptom | First action |
|---|---|---|
| Password sign-in | Email/password rejected | Check exact invited work email; use Forgot password instead of repeated guessing |
| Social sign-in | Provider returns an auth error | Use the provider already linked to the approved account; social sign-on is for existing approved accounts |
| MFA | Password accepted but authenticator challenge fails | Verify device time and current code; use approved recovery if device is lost |
| Recovery link | Invalid or expired | Request a new Forgot password link; use only the latest link |
| Invitation delivery | Pending invite exists but no email | Administrator checks sent/skipped/failed delivery result and resends if authorized |
| Invitation acceptance | Invite invalid/expired or password setup fails | Administrator removes stale invite and issues a new one to the exact email |
| Workspace access | Sign-in works but workspace is absent | Check active workspace membership, status, and invited workspace targets |
Sign-in, organization membership, and workspace access are separate gates
- 01AccountOrganization
The customer account and ownership boundary.
- 02ScopeWorkspace
The operating area where customer work and configuration live.
- 03GovernOwner
Controls the organization, subscription, and highest-risk access.
- 04ConfigureAdministrator
Configures members, channels, defaults, and operating controls.
- 05OperateMember
Works customer queues, records outcomes, and escalates exceptions.
User recovery
- Go to Login and use the exact invited work email.
- Try the intended method: password or the already approved social provider.
- If the password is unknown, select Forgot password and request one link.
- Open the newest message in the same browser context where practical.
- For an invitation, set a password of at least the displayed minimum length and confirm it.
- Complete authenticator MFA if enrolled.
- After sign-in, use the workspace switcher and verify the intended slug.
Do not request many recovery emails; older links may expire or be superseded. Never forward an invitation or recovery link to another person.
Administrator invitation checks
- Open Settings → Members and filter Invited.
- Confirm normalized email, role, created date, and targeted workspace.
- Read the original result: email sent, saved but not sent, or saved but failed.
- If the same-role pending invitation exists, use Resend invitation where organization authority permits.
- If the role is wrong, remove the pending invite before sending one with a different role.
- If the person already belongs to the organization, add them as an existing organization member instead of inviting a duplicate identity.
- Confirm seat capacity and organization authority when creating a brand-new user.
A Workspace Admin can add existing organization Members; organization Owner/Admin authority is required to invite a brand-new organization user. A pending invite may target more than one workspace, so remove only the intended workspace target unless global revocation is authorized.
MFA or suspicious access
If an unknown session or repeated auth errors accompany the issue, stop treating it as a simple invitation problem. End sessions, change password, verify MFA, and have the Owner review Session logs.
Escalation packet
Provide work email, invitation ID, targeted workspace slug, role, delivery status/reason, auth error code/message, approximate time/timezone, browser/provider, and whether password or social sign-in was used. Never provide password, invitation token/link, recovery token, MFA code/QR secret, cookies, or session tokens.
- Exact approved work identity used
- Newest recovery/invite link used once
- Pending invite role and workspace targets verified
- Existing member was not duplicated
- MFA and sessions checked when risk signals appeared
- No token, link, password, or code shared