People join a tenant by invitation. The tenant's Invitations page sends invitations, follows them until they are accepted, and renews guests.
Inviting a member
Enter the person's email address and choose Send invitation. They receive an email and join once they sign in with that address; the link is valid for 72 hours. Members always receive the tenant's default app roles (setting Default app roles); tick any extra role to give on joining. You can only give roles you may assign yourself.
The tenant may accept members only from its allowed email domains (setting Member email domains).
Inviting a guest
A guest is someone from outside the tenant, invited for limited collaboration. Switch on Invite as a guest before sending. Guests hold only the guest role, can't join units or subgroups, and can't be given administrative roles.
Who may invite guests depends on the setting Who may invite guests: nobody, administrators only, or any member. Guests may have to come from the allowed guest domains.
Guest expiry and renewal
Guest access lasts a set number of days after the guest accepts (setting Guest access (days), 90 by default). To extend it, choose Renew next to the guest; the new period starts from today.
Platform staff
Shokoofa platform staff (anyone with a platform role) can't hold roles in customer tenants. Inviting their address, as a member or a guest, is refused. If an invitation reaches a staff account anyway, My invitations lists it without an Accept button and explains why; ask for a different, non-staff account to be invited instead.
Pending invitations
Pending invitations are listed with their expiry. Revoke stops a link from working; you can invite the person again later. Switch on the full list to also see accepted, revoked and expired invitations.