As an account admin, you may be wondering which members of your account can invite other users. This is a great question! When it comes to inviting users to your account, your account's login settings will affect who will be able to invite others.
In this article, we'll look at authentication policies and how they affect who can invite users. Let's get to it!
Email & Password
How does this setting work?
Admins have better flexibility in managing login policies with the ability to customize the email and password policy. This setting makes it easy to exclude specific users from the SSO requirement, offering a flexible solution to adapt login preferences to your team’s unique needs.
When clicking on the three dots next to the "Email and password" under the Authentification policies section and choosing "Edit", the admin can select the policy members, meaning they can define who the email and password policy applies to—everyone or only some people (e.g., guests, a single user).
Before activating SSO, the email and password policy cannot be modified. By default, after SSO is activated, the email and password policy changes from "Everyone" to "Guests."
There are two options in the email and password policy section:
Option 1: All users (including guests) can log in to monday.com using the email and password policy.
Option 2: Only some people (guests, single user, or both) can use the email and password policy to log in to monday.com.
Choosing "Guests" under "Only some people" would mean that guests can log in using the email and password policy (not only SSO). This is the most commonly used policy option since oftentimes guests are external users not managed by an organization's internal IT.
Choosing "A single user" under "Only some people" would mean that only one chosen team member can log in using the email and password option (not only SSO).
If applicable to your company’s security policy, we recommend using the "Guests" or "Guests and a single user" options under "Only some people" policy members. This means every user on the account, aside from guests and the designated single user, is required to log in using SSO. Guests can be invited to shareable boards and log in using an email and password as normal. In this case, guest emails do not need to be active in the account's IDP to log in. The single-user option provides additional flexibility, allowing one team member to log in using email and password for emergency access if needed.
Who can invite users with this setting?
- Admins can invite anyone to the account as any user type.
- Members can only invite guests to Shareable Boards that they are the board owner of.
-
If a member wants to invite a new user to the account, they will be able to send a request to their admin(s):
When a member uses this option, an email and a bell notification will be sent to all account admins.
Authorized email domain
How does this setting work?
The authorized email domain setting allows you to define a specific email domain that all users (aside from guests) must have in order to join the account. Additionally, with this setting, any person with this specified email domain can also join the account themselves without an invitation.
Who can invite users with this setting?
- Admins can invite any user type, even if they do not have the authorized email domain.
- Members can invite other members or viewers with the authorized email domain. Additionally, members can invite guests onto Shareable Boards that they are the board owner of.
- Viewers can invite other viewers who have the authorized email domain.
Google SSO (single sign-on)
How does this setting work?
Google SSO, a secure authentication system, allows your team members to easily sign into monday.com using their Google account. If your organization's email domain is hosted by Google, users who have that specified Google domain will be able to sign up to the account without an invitation.
Who can invite users with this setting?
- Admins can invite any other user type as long as they have the same Google domain specified in their SSO setup. Guests with other domains can be invited by admins as well.
- Members can invite other members or viewers as long as they have the same Google domain specified in their SSO setup. Additionally, members can invite guests onto Shareable Boards that they are the board owner of.
- Viewers can invite other viewers if they have the same Google domain as specified in their SSO setup.
SAML SSO (single sign-on)
How does this setting work?
Using SAML SSO, an organization's IT or Operations team can easily manage all user login credentials across multiple applications at once. Having this in place provides an extra layer of security and allows you and your team to seamlessly log into various platforms using the same set of credentials.
Who can invite users with this setting?
- Admins can invite any user type to join the account.
- Members can only invite guests onto Shareable Boards that they are the board owner of.
Managing requests
You can manage all pending invitations from the Administration section of your account. To find this page, go to Administration > Users > Pending Invitations.
If you have any questions, please reach out to our team right here. We’re available 24/7 and happy to help.