Invitations use safe role presets rather than a permission matrix, so you can get your team in quickly without accidentally granting more access than you meant to.
#01How invitations work
- You enter a work email, choose a starting role and set a scope. Three rows appear by default; add more without leaving the screen.
- Invitations are unique to one person and expire after 7 days.
- Each link works once. Resending immediately invalidates the previous unused link.
- Invitations should never be forwarded. If somebody forwards one, ask them to tell you so it can be cancelled.
- Skipping this step is fine. Doing it later takes about 30 seconds.
#02How many people you can invite
The Workspace Owner occupies one staff account, so your invitation allowance is one fewer than your plan’s total.
| Plan | Staff accounts | Invitations available to you | Bulk options |
|---|---|---|---|
| Community | 3 | 2 | None — upgrade for more |
| Every paid plan | As set out in your plan or Order Form | Your included accounts, less the one you are using | As included in your plan or Order Form |
You are told before you run out. Academyship blocks a fourth Community account before you type an address, showing the exact included and used counts. You will never fill in ten rows and then be told at submit that only two were allowed.
For a large team, do not type addresses. Where directory provisioning is included in your plan or Order Form, invite the handful of colleagues who will help you launch, then connect your directory so accounts are created and removed automatically. Typing hundreds of addresses is not the intended path.
#03The nine role presets
Presets describe responsibility in plain language: the areas a role reaches, the actions it allows there, and what it excludes. Access is checked whenever somebody tries to do something, not by what a screen shows. Detailed permissions are refined later in the Setup Centre — a full permission matrix is deliberately not shown during Quick Launch.
| Preset | What it is for | Excluded by default |
|---|---|---|
| Workspace Owner | Institution control, billing, security and ownership | Only one primary owner. Transfer requires re-authentication and is audited. |
| Super Admin | Broad product administration across the workspace | Ownership transfer and contract authority |
| Academic Manager | Courses, hierarchy, assessments and academic reporting | Billing, payroll and security policy |
| Compliance / RTO Manager | Compliance records, USI/AVETMISS and audit exports where entitled | Billing, payroll and user-role administration |
| Admissions / Student Services | Prospects, applications, enrolments and student services | Payroll, security and destructive bulk actions |
| Teacher / Trainer | Assigned classes, attendance, assessment and learner communication | Institution-wide exports, billing and role administration |
| Finance | Fees, invoices, payments and finance reporting | Academic configuration, security and payroll unless added |
| Front Office | Contact records, attendance follow-up and approved communications | Finance exports, payroll and configuration |
| Read-only Auditor | Scoped viewing and export for audit | Create, edit, delete, invite or configure |
#04Least-privilege rules
- Scope narrows access before custom permissions widen it. Campus, cohort and module scopes apply first.
- Exports, impersonation, role administration, API keys, payroll, billing, deletion and security policy all require explicit elevation — no preset grants them silently.
- Ownership transfer and high-risk permission changes require recent multi-factor authentication and generate audit notifications.
- Presets are versioned, so you can see which version of a role definition somebody was given.
#05What your colleague experiences
An invited staff member never sees institution setup — no calendar, no hierarchy, no plan choices, no billing. Their whole flow takes about two minutes, or about three to five minutes where an authenticator app is required and they do not already have one.
- Verify the invited email with an explicit action, so scanners cannot consume the invitation.
- Create a sign-in — a password of 12 to 128 characters; length is the rule, not a mixture of symbols. On a shared device, a password is recommended and saving the password in the browser is discouraged. See Passwords.
- Accept the terms as a user — the same Terms of Service and Acceptable Use Policy that bind your institution, with the Privacy Policy to acknowledge. There is no separate set of user terms; the acceptance is recorded in your colleague’s own name. They are never asked to accept your institution’s commercial agreement.
- Turn on multi-factor authentication if your institution’s plan requires it. Every paid plan requires it; on Community it is optional with no deadline, though it is always recommended.
- Confirm their display name, which appears on records they create and on class rolls.
- Land on a home view for their role, showing three things that role can do straight away.
#06If invitations are locked
On Community, an owner who has deferred multi-factor authentication cannot invite anybody yet. Inviting staff is one of the nine actions that stay locked for the whole deferral window, along with importing real data, exports, certificates, API keys, privileged roles, employee files, ownership changes and destructive bulk actions.
Why inviting waits. An account with only a password must not be able to hand out access to student records — creating a second administrator is how an intruder keeps access after a password is changed. Quick Launch lets you skip the invite step and come back to it; skipping records it as skipped, not as done. Every locked action becomes available the moment multi-factor authentication is on. See Account security.
#07Keep reading
These four guides cover the whole onboarding journey.