Appearance
Set up sign-in and invite your team
Every set-up starts here. Your IT or security lead decides how people sign in, and a Flowstate admin invites people and gives them roles.
A login isn't the same as a person in your people data. Most people you load never sign in, and a login is linked to a person by their work email. See People records and logins are different things.
Before you start
- You need to be signed in as a Flowstate admin (the Administrator role).
- Have a list of your company email domains, and the first people who need access with the job each of them does.
1. Restrict sign-in to your email domains
What: Only let people with your company's email addresses sign in, and choose how long they stay signed in. Who: IT or security lead. Where: Settings → Organisation → Authentication. Done when: Your domains are listed under Allowed Email Domains, and Session Duration shows the length you chose.
- Leave Allowed Email Domains empty to allow any domain. A domain also allows its subdomains.
- Someone you invite from another domain can sign in the first time through their invitation. After that, they can only sign in if their domain is on the list. So add the domain of any contractor or partner who'll keep using Flowstate.
- Session Duration can be from 1 hour to 90 days, and starts at 7 days. People are also signed out after a period of inactivity.
2. Choose how new people join
What: Decide whether anyone at your company can create their own account, or only people you invite. Who: IT or security lead. Where: Settings → Organisation → User Enrollment. Done when: You've saved your choice with Save Enrollment Settings.
Choose one:
| Option | How it works | Trade-off |
|---|---|---|
| Automatically enroll new users (on unless you change it) | Anyone on an allowed domain gets an account the first time they sign in, with the Default Role you pick. | No invitations to manage, but everyone on your domain gets in. Pick a low-access default role such as Viewer. |
| Invite only (untick the box) | Only people you invite can sign in. | You control every account, but have to invite each person. |
3. Invite your first users
What: Send invitations to the people who will set Flowstate up. Who: Flowstate admin. Where: Settings → Users & Access → Users, then Invite User. Done when: Each person appears under Pending, then moves to Active after they first sign in.
- Select Invite User.
- Enter their Email, and their Name if you like. Use the same work email as their people record, so Flowstate knows which person the login belongs to.
- Choose a Role, or leave No Role (use default). You can only give roles with permissions you have yourself.
- Select Send Invitation.
They'll get an email with an Accept Invitation button. Invitations don't expire. From the person's row you can Resend Invitation or Revoke Invitation.
4. Give each person the right role
What: Make sure each person can see and change only what their job needs, especially salaries and costs. Who: Flowstate admin, agreed with your Finance lead. Where: Settings → Users & Access → Roles to review roles. To change someone's role, go to Settings → Users & Access → Users and select Edit User on their row. Done when: Everyone under Active has a role that matches their job.
Flowstate comes with these roles, marked System:
| Role | Intended for |
|---|---|
| Administrator | Full access to all features and settings. |
| Config Admin | All settings, teams and roadmap, with no financial visibility. |
| Financial Manager | Full financial visibility and team management, with control of pay. |
| Team Manager | All team and roadmap management, with no financial visibility or pay control. |
| Line Manager | Financial visibility and management for their own teams. Can approve effort. |
| Team Member | Can see everything except financials. Can submit effort. |
| Viewer | Read-only access to non-financial data. |
| AI Viewer | Sees only their own AI usage. |
| Tenant Admin | Settings only, for looking after the account. Can't see organisation data. |
- To make your own role, select Create Role, or Duplicate Role on an existing one and adjust it. System roles can't be deleted.
- Unless their role gives them organisation-wide visibility, people only see the teams they manage and the teams beneath them. This is how line managers see just their own area.
What each permission allows: Roles and permissions.
5. Optional: set up single sign-on
What: Let people sign in through your identity provider instead of an emailed link. Who: IT or security lead. Where: Settings → Organisation → Single Sign On, then Add Provider. Done when: A test user on your SSO domain is sent to your identity provider when they enter their email, and lands in Flowstate afterwards.
Choose one:
| Option | Trade-off |
|---|---|
| Flowstate sign-in (nothing to set up) | People sign in with an emailed link and a second factor, or with a passkey. Accounts aren't tied to your identity provider. |
| Single sign-on with SAML 2.0 or OAuth 2.0 | Sign-in follows your identity provider's rules, and you can map groups to roles. Flowstate doesn't ask for its own second factor on SSO sign-ins, so require multi-factor authentication in your identity provider. |
- Enter the Email Domains the provider covers. Anyone signing in with one of those domains is sent to it.
- If you add Group Mappings, people who aren't in any mapped group can't sign in.
Step-by-step guides: SAML 2.0 · OAuth 2.0.
6. Optional: provision users automatically with SCIM
What: Let your identity provider create, update and remove Flowstate users. Who: IT or security lead. Where: Settings → Users & Access → SCIM Provisioning, then Create Token. Done when: Adding a person to a mapped group in your identity provider gives them a Flowstate account with the mapped role.
SCIM works through groups: people get an account and a role, or lose access, based on the groups you've mapped on your single sign-on provider. Set up single sign-on first. See SCIM 2.0 provisioning.
SCIM only manages logins. It doesn't add anyone to your people data: load people separately, as described in Get your people data into Flowstate.
How people sign in
- The person enters their email address on the sign-in page.
- If they have a passkey, their browser asks for it and they're signed in. If their email domain uses single sign-on, they're sent to your identity provider. Otherwise, Flowstate emails them a sign-in link.
- After an emailed link, Flowstate asks for a second factor. The first time, they set up Passkey (recommended) (Face ID, Touch ID, Windows Hello or a security key) or an Authenticator app such as Google Authenticator or 1Password.
Good to know:
- Someone with a passkey and no authenticator app signs in with their passkey, not an emailed link.
- If someone loses their phone or passkey, an admin selects Reset MFA on their row under Settings → Users & Access → Users. They set up a second factor again next time they sign in.
- After too many wrong authenticator codes, the person has to wait a while before trying again.
- People add or remove passkeys and authenticator apps in the Security section of their profile.
Removing access
To stop someone signing in, select Suspend User on their row under Settings → Users & Access → Users. They move to Suspended until you select Reactivate User. If you use SCIM, remove them from the mapped group in your identity provider instead.
Suspending a login doesn't record a leaver. If they've left, also give them an end date in your people data, or in your HR system if that's the source of truth.
You're set up when
- Your email domains and session length are saved under Authentication.
- Your enrolment choice is saved under User Enrollment.
- The people setting Flowstate up are Active, each with the role their job needs.
- Each of them has signed in and set up a second factor, or signs in through your identity provider.
More detail
- Get your people data into Flowstate: where your people data comes from, and how logins link to people.
- Users and roles: day-to-day user admin.
- Sign-in settings: every sign-in setting explained.
- Roles and permissions: what each permission allows.
- SAML 2.0, OAuth 2.0 and SCIM 2.0: set-up for your identity team.