Skip to main content
Help Centre · Getting started

Invite staff and role presets

About 2 minutes · Skippable — about 30 seconds to do later · Least privilege by default · Last updated 29 August 2026

Invitations use safe role presets rather than a permission matrix, so you can get your team in quickly without accidentally granting more access than you meant to.

#01How invitations work

  • You enter a work email, choose a starting role and set a scope. Three rows appear by default; add more without leaving the screen.
  • Invitations are unique to one person and expire after 7 days.
  • Each link works once. Resending immediately invalidates the previous unused link.
  • Invitations should never be forwarded. If somebody forwards one, ask them to tell you so it can be cancelled.
  • Skipping this step is fine. Doing it later takes about 30 seconds.

#02How many people you can invite

The Workspace Owner occupies one staff account, so your invitation allowance is one fewer than your plan’s total.

Staff accounts and invitations by plan.
PlanStaff accountsInvitations available to youBulk options
Community32None — upgrade for more
Every paid planAs set out in your plan or Order FormYour included accounts, less the one you are usingAs included in your plan or Order Form

You are told before you run out. Academyship blocks a fourth Community account before you type an address, showing the exact included and used counts. You will never fill in ten rows and then be told at submit that only two were allowed.

For a large team, do not type addresses. Where directory provisioning is included in your plan or Order Form, invite the handful of colleagues who will help you launch, then connect your directory so accounts are created and removed automatically. Typing hundreds of addresses is not the intended path.

#03The nine role presets

Presets describe responsibility in plain language: the areas a role reaches, the actions it allows there, and what it excludes. Access is checked whenever somebody tries to do something, not by what a screen shows. Detailed permissions are refined later in the Setup Centre — a full permission matrix is deliberately not shown during Quick Launch.

The nine role presets, what each is for, and what it excludes by default.
PresetWhat it is forExcluded by default
Workspace OwnerInstitution control, billing, security and ownershipOnly one primary owner. Transfer requires re-authentication and is audited.
Super AdminBroad product administration across the workspaceOwnership transfer and contract authority
Academic ManagerCourses, hierarchy, assessments and academic reportingBilling, payroll and security policy
Compliance / RTO ManagerCompliance records, USI/AVETMISS and audit exports where entitledBilling, payroll and user-role administration
Admissions / Student ServicesProspects, applications, enrolments and student servicesPayroll, security and destructive bulk actions
Teacher / TrainerAssigned classes, attendance, assessment and learner communicationInstitution-wide exports, billing and role administration
FinanceFees, invoices, payments and finance reportingAcademic configuration, security and payroll unless added
Front OfficeContact records, attendance follow-up and approved communicationsFinance exports, payroll and configuration
Read-only AuditorScoped viewing and export for auditCreate, edit, delete, invite or configure

#04Least-privilege rules

  • Scope narrows access before custom permissions widen it. Campus, cohort and module scopes apply first.
  • Exports, impersonation, role administration, API keys, payroll, billing, deletion and security policy all require explicit elevation — no preset grants them silently.
  • Ownership transfer and high-risk permission changes require recent multi-factor authentication and generate audit notifications.
  • Presets are versioned, so you can see which version of a role definition somebody was given.

#05What your colleague experiences

An invited staff member never sees institution setup — no calendar, no hierarchy, no plan choices, no billing. Their whole flow takes about two minutes, or about three to five minutes where an authenticator app is required and they do not already have one.

  1. Verify the invited email with an explicit action, so scanners cannot consume the invitation.
  2. Create a sign-in — a password of 12 to 128 characters; length is the rule, not a mixture of symbols. On a shared device, a password is recommended and saving the password in the browser is discouraged. See Passwords.
  3. Accept the terms as a user — the same Terms of Service and Acceptable Use Policy that bind your institution, with the Privacy Policy to acknowledge. There is no separate set of user terms; the acceptance is recorded in your colleague’s own name. They are never asked to accept your institution’s commercial agreement.
  4. Turn on multi-factor authentication if your institution’s plan requires it. Every paid plan requires it; on Community it is optional with no deadline, though it is always recommended.
  5. Confirm their display name, which appears on records they create and on class rolls.
  6. Land on a home view for their role, showing three things that role can do straight away.

#06If invitations are locked

On Community, an owner who has deferred multi-factor authentication cannot invite anybody yet. Inviting staff is one of the nine actions that stay locked for the whole deferral window, along with importing real data, exports, certificates, API keys, privileged roles, employee files, ownership changes and destructive bulk actions.

Why inviting waits. An account with only a password must not be able to hand out access to student records — creating a second administrator is how an intruder keeps access after a password is changed. Quick Launch lets you skip the invite step and come back to it; skipping records it as skipped, not as done. Every locked action becomes available the moment multi-factor authentication is on. See Account security.

#07Keep reading

These four guides cover the whole onboarding journey.