What it is
Self-enrollment lets collaborators join the platform on their own, through a public link, without you inviting them one by one. It is opt-in and always restricted by a domain allowlist. Only emails from the domains you authorize can sign up.
You configure it in Settings → Self-enrollment (/settings/enrollment), TENANT_ADMIN access.
How it works
- You enable self-enrollment and define the domain allowlist (required; without a domain, it won’t turn on).
- The platform generates an enrollment link with a token (regenerable and revocable). You distribute this link to collaborators.
- The collaborator opens the link, enters their email and follows the chosen mode.
The enrollment link must point to the collaborator host (app.…), not the admin console. The platform already adjusts this when generating the link.
Modes
| Mode | Flow |
|---|---|
| OTP | The collaborator confirms the email with a code and is activated immediately |
| Approval | The sign-up stays pending approval; you approve it in Users, and the first OTP login confirms the email (a double check) |
Security controls
- Domain allowlist required.
- Plan user limit enforced; duplicates blocked.
- Captcha (Turnstile) optional to curb abuse.
- Everything is audited (
user.self_register,user.approved,user.rejected).
Follow-up
The screen itself has a Sign-ups tab with the list (name, email, area, status, date) for reference. Approval/rejection happens on the Users screen (status “Pending approval”).
Related
</content>