Appearance
Invite people and manage their access
Add people to Flowstate, change what they can see, and get someone back in after they lose their phone or passkey. First time setting up? Start with Sign-in and access.
You need to be a Flowstate admin.
Find people
Go to Settings → Users & Access → Users. People are split into three tabs:
| Tab | Who's in it |
|---|---|
| Active | People who can sign in |
| Pending | People you've invited who haven't signed in yet |
| Suspended | People you've stopped from signing in |
Invite someone
- Go to Settings → Users & Access → Users and select Invite User.
- Enter their Email, and their Name if you like.
- Choose a Role, or leave No Role (use default).
- Select Send Invitation.
They appear under Pending, then move to Active the first time they sign in. From the menu on their row you can Resend Invitation or Revoke Invitation.
Not sure which role to choose? See Roles and permissions.
Change someone's name, email or role
- Open the menu on their row and select Edit User.
- Change their Name, Email or Role.
If your identity provider sets roles from groups, change the person's group there instead. Otherwise their role changes back the next time they sign in or their groups change.
Reset someone's second factor
Do this when someone has lost the phone or passkey they sign in with.
- Open the menu on their row and select Reset MFA.
- Confirm.
All their passkeys and authenticator apps are removed. Next time they sign in, Flowstate emails them a link and asks them to set up a second factor again. Before you reset, make sure you're talking to the right person.
Suspend or reactivate someone
- Select Suspend User on their row to stop them signing in. They move to Suspended.
- Select Reactivate User on a suspended person to let them sign in again.
If you use SCIM, remove the person from their groups in your identity provider instead. See Provision accounts with SCIM.
Create your own role
- Go to Settings → Users & Access → Roles.
- Select Create Role. Or, to start from a role that's close to what you need, open its menu and select Duplicate Role.
- Enter a Name and Description.
- Choose a Dashboard View Mode.
- Tick the Permissions.
- Select Create.
Built-in roles have a System badge and can't be deleted. To remove a role you made, move people off it, then select Delete Role from its menu.
Change a role's permissions
- Go to Settings → Users & Access → Roles.
- Open the menu on the role's row and select Edit Role.
- Tick or untick Permissions. You can also change the Name, Description and Dashboard View Mode.
- Select Update.
The change applies to everyone with that role. Permissions your own role doesn't have are greyed out and marked "(You don't have this permission)".
Tip
Built-in roles can be changed too. To keep a built-in role as it is, select Duplicate Role from its menu and change the copy instead.
Choose what new people get when they join
This decides what happens when someone signs in for the first time without an invitation.
- Go to Settings → Organisation → User Enrollment.
- Turn Automatically enroll new users on or off. When it's on, anyone allowed to sign in gets an account the first time they do.
- Choose a Default Role for those people. The list runs from least access to most.
- Select Save Enrollment Settings.
Tip
Choose a low-access default, such as Viewer, and give people more access one by one.
With automatic enrolment off, only people you invite, or people your identity provider adds, can get in.
If something's not right
"Cannot invite with this role: it contains permissions you do not have". The role includes permissions your own role doesn't have. Choose a smaller role, or ask someone with more access to send the invitation.
"Cannot grant permissions you do not have: …" when you select Update. The role has permissions your own role doesn't have, so you can't save changes to it. Ask someone with more access to edit it.
Someone sees "You are not authorised to access this organisation." Automatically enroll new users is off and they haven't been invited. Invite them.
Reset MFA isn't in the menu. The person hasn't set up a second factor yet, or they're still under Pending.
A role you changed keeps changing back. Their role comes from your identity provider. Move them to a different group there.
A manager can see the pay in another team's budget. Anyone asked to approve a team's budget can see the pay in the changes they review, whatever their role. That includes the manager of the team above and anyone your organisation names as a budget approver. To stop it, change who approves that team's budget. See Choose who approves budgets.
Someone selects Approve on a budget and sees "Forbidden: You do not have the required permission". Their role doesn't have Approve Budget Proposals. Add it to their role, or ask another approver to approve it.
Someone selects Approve on a week of effort and sees "Failed to approve — please try again." Check their role has Approve Effort. Being listed as an approver in Settings → Scenarios → Review Workflow isn't enough on its own. See Approve or send back a week.