> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://docs.brainframe.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Workspace Users

# 👥 **Workspace Users**  
> **"Secure access, tailored permissions."**  
> *Manage who can log in, what they can see, and how they interact within each workspace.*

---

## 1️⃣ Overview
Brainframe **users** are individuals who require login access to the system.  
Their ability to navigate and perform actions depends on the **permissions** granted.  

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/screenshot-2026-07-12-at-21053_j7vl20.png =772xauto)
**Key points:**
* Each user is tied to a **unique login email**.  
* Users may belong to **multiple workspaces**.  
* Roles, permissions, and visibility are defined **per workspace**.  

---

## 2️⃣ Inviting Users
You can invite new or existing users to a workspace.  
An **email invitation** notifies them of their access.  

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/29_1u2bybg.png =783xauto)
1. **Invite users** — Send an invitation by entering their email address.  

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/screenshot-2026-02-18-at-10492_14yb4bm.png =373xauto)
| By toggling "Do not send invite", you can add a user to the workspace, but without providing them the link to it. This allows you to assign them to tasks and documents, and giving them their actual access later on.


2. **Assign admin role** — Admins gain access to configuration areas, including *Settings*, *Forms*, *Distributions*, and *SOA*.  
3. **Enable or disable users** —  
* Users cannot be fully deleted (for audit traceability).  
* Instead, toggle between **Active** (green) and **Inactive** (red).  
* Inactive users cannot access the workspace and may be logged out after up to 15 minutes.  
4. If SSO is configured at the workspace, you can disable the option for users to log in with a password, and force SSO.
5. **Alias support** — Modify how a user is displayed in a workspace (e.g., using a different name or email specific to that organization).  


| INFO: Only active users count toward your license thresholds.

---

## ✅ Best Practices
* 🔑 **Use role-based permissions** — Assign roles to maintain least-privilege access.  
* 🛡 **Disable unused accounts** — Keep your license count accurate and reduce risk exposure.  
* 📧 **Verify email aliases** — Ensure workspace-specific names or emails are correct before modifying.  

---

## 🎯 Visual Checklist
* [x] Users invited successfully  
* [x] Admins assigned where needed  
* [ ] Inactive accounts reviewed and disabled  
* [x] Email aliases configured correctly  
