App
Identity & tenantsCross-tenant invitations
Identity & tenants

Cross-tenant invitations

When someone works for several organisations — a service provider, an external technician, a person holding two roles in a group of companies — there is no need for a second account. An existing HGE ID can be invited straight into another tenant.

#Who may invite

The users:manage permission is enough. User management offers two actions side by side:

  • New user — creates a new account
  • Invite existing HGE ID — invites someone who already holds an HGE ID

#What happens on invite

  1. The email address entered is checked against existing HGE IDs
  2. An invitation is created, valid for 7 days
  3. A notification is placed in every tenant the person already belongs to — they see it on the bell at their next sign-in, whichever tenant happens to be active
  4. You always get the same response: "Invitation sent"
Note
Point 4 is deliberate. If the interface distinguished whether the address exists, it could be used to probe who uses Uslimato. The answer is therefore always identical.

#Accepting or declining

The invited person opens Profile › Invitations or clicks the notification directly.

  • Accept — a user account is created in the target tenant; after the reload the tenant switcher shows the new membership
  • Decline — the invitation is recorded as declined

#What administration sees afterwards

People who accepted appear in the user list marked **"External · *tenant*", spelled out in the detail view as "Managed by *tenant*"**. That makes it immediately clear that name, email and profile picture come from the Master tenant and cannot be changed here.

Everything else stays with you: roles, groups and permissions are granted per tenant. You decide entirely what this person may see and do at your place.

#Security

  • At most 10 invitations per tenant per hour
  • Invitation tokens are never stored in clear text
  • The email match happens on the server: signed-in users only ever see and answer their own invitations
  • Creation, acceptance and decline each land in the audit log of the tenant concerned

#Not possible yet

  • If the person has no HGE ID at all, the notification cannot reach them — sending an email for that case follows in a later iteration. Until then, create a new account for such people
  • Display name and profile picture are held per tenant; reconciliation with the master tenant happens at that person's next sign-in
Was this helpful?
Suggest an edit