Cross-tenant invitations
When someone works for several organisations — a service provider, an external technician, a person holding two roles in a group of companies — there is no need for a second account. An existing HGE ID can be invited straight into another tenant.
#Who may invite
The users:manage permission is enough. User management offers two actions side by side:
- New user — creates a new account
- Invite existing HGE ID — invites someone who already holds an HGE ID
#What happens on invite
- The email address entered is checked against existing HGE IDs
- An invitation is created, valid for 7 days
- A notification is placed in every tenant the person already belongs to — they see it on the bell at their next sign-in, whichever tenant happens to be active
- You always get the same response: "Invitation sent"
#Accepting or declining
The invited person opens Profile › Invitations or clicks the notification directly.
- Accept — a user account is created in the target tenant; after the reload the tenant switcher shows the new membership
- Decline — the invitation is recorded as declined
#What administration sees afterwards
People who accepted appear in the user list marked **"External · *tenant*", spelled out in the detail view as "Managed by *tenant*"**. That makes it immediately clear that name, email and profile picture come from the Master tenant and cannot be changed here.
Everything else stays with you: roles, groups and permissions are granted per tenant. You decide entirely what this person may see and do at your place.
#Security
- At most 10 invitations per tenant per hour
- Invitation tokens are never stored in clear text
- The email match happens on the server: signed-in users only ever see and answer their own invitations
- Creation, acceptance and decline each land in the audit log of the tenant concerned
#Not possible yet
- If the person has no HGE ID at all, the notification cannot reach them — sending an email for that case follows in a later iteration. Until then, create a new account for such people
- Display name and profile picture are held per tenant; reconciliation with the master tenant happens at that person's next sign-in