User access
Tenant and partner user invites
Invite users into the right tenant, manage partner workflows, and understand pending/used/expired invite states.
Updated April 27, 2026 | 7 min
Recommended invite workflow
- Go to Settings and open the Invite user section.
- Select the target tenant first. This determines where the user account is created.
- Choose invite role (tenant_admin, analyst, read_only, and partner_admin for super-admin paths).
- Enter email if you want ITDR to email the registration link directly, or leave it blank and share the generated link manually.
- After invite creation, track status in Users -> Invites (pending, used, expired).
Role and tenant boundaries
Tenant admin: can invite users only within their tenant.
Partner admin: can invite users for tenants in their managed organization.
Super admin: can invite across tenants and create/promote partner-level users.
Partner admin and MSP patterns
Create customer tenant first, then send tenant-specific invite.
For MSP setup, create partner organization and partner tenant before assigning customer tenants.
Use Assign tenant to partner when moving a standalone customer under an MSP tenant.
Validation checklist
Invite status should move from pending to used after registration completes.
If invite expires (7-day window), create a new invite token.
Use the tenant selector in Users page to verify the user is in the intended tenant.