User access

Tenant and partner user invites

Invite users into the right tenant, manage partner workflows, and understand pending/used/expired invite states.

Updated April 27, 2026 | 7 min

Recommended invite workflow

  1. Go to Settings and open the Invite user section.
  2. Select the target tenant first. This determines where the user account is created.
  3. Choose invite role (tenant_admin, analyst, read_only, and partner_admin for super-admin paths).
  4. Enter email if you want ITDR to email the registration link directly, or leave it blank and share the generated link manually.
  5. After invite creation, track status in Users -> Invites (pending, used, expired).

Role and tenant boundaries

Tenant admin: can invite users only within their tenant.

Partner admin: can invite users for tenants in their managed organization.

Super admin: can invite across tenants and create/promote partner-level users.

Partner admin and MSP patterns

Create customer tenant first, then send tenant-specific invite.

For MSP setup, create partner organization and partner tenant before assigning customer tenants.

Use Assign tenant to partner when moving a standalone customer under an MSP tenant.

Validation checklist

Invite status should move from pending to used after registration completes.

If invite expires (7-day window), create a new invite token.

Use the tenant selector in Users page to verify the user is in the intended tenant.