Skip to main content

Overview

This page covers the day-to-day work of giving people access: inviting a team member, adding an app user, and managing who has what. You pick from roles that already exist, so there’s nothing to build. If you instead need to create roles or decide what each one can do, that’s a separate job covered in Members & Roles. There are three kinds of people you’ll add, and each lives in a different place:
The public pages of a deployed app are open to anyone by default, so no invitation is needed. You only invite people when they need to sign in to do something authenticated.

Creating accounts directly

Organization admins can create accounts for people who do not already have a sign-in:
  • Settings → Members → Create accounts creates team members with the selected organization role. App-only roles are supported.
  • A public app’s Settings → App Users → Create accounts creates customer app users with the selected app role. Enable email and password sign-in for that app first.
The dialog opens with a list of people. Type an email, and optionally a first and last name, on each row, and use Add person for more rows. Add from file adds the rows of a CSV or Excel (.xlsx) file to the list, and you can add more by hand or from other files afterwards. Clear list starts over. Rows you leave empty are skipped. Each row can set its own role. When creating team members, a row can also give access to one app with an app role, and can name an existing person from the people directory. A row that leaves the role blank uses the Default role chosen below the list. In a file, the first row holds the headers. email is required; the others are optional: The dialog lists the keys that role, app and app_role accept, with a copy button for each, and offers a CSV template and an Excel template to start from. Excel uses the first worksheet; format cells as text. A file can be up to 2 MB, and files can fill the list up to 1,000 people.
Rows that can’t be sent are marked with the reason, such as an invalid or duplicate email, an unknown role or app key, or the same person picked on two rows. Fix or remove them before you create the accounts.

Giving the login to someone already in the directory

When the person already appears in Identities, for example as a customer or a contact, pick them in the Person column (or put their id in the identity column). Their new team login is added to that person instead of creating a second one. If the row has no name, the account takes the person’s name.
  • Picking a person requires the identities:govern permission.
  • Only people with no team login are offered. A request that names a person who already has one, or who was merged or archived, is refused before any account is created.
  • If the account is created but can’t be added to the person, the result says so. The account works; merge the two people from Identities.
Passwords are autogenerated by default, even when the file contains passwords. Select Use supplied passwords to use them; blank passwords are still generated. Supplied passwords must meet your sign-in password rules. A password that doesn’t is reported on its row, with the rule it broke, and that account isn’t created. Review each result, then Download credentials (.xlsx) before closing. Passwords are available only in those results; share them securely with each person. No invitation email is sent by this action. An existing account is skipped and its password is never changed; use the invitation flow to add that person. Large lists are sent in batches of 20. If a batch fails partway, the results keep the credentials already created, and Back to unsent people returns to the rows that weren’t sent. Save the credentials first: going back leaves the results. If your organization has reached its member limit (pending invitations count toward it), the row fails with that reason and no account is left behind. Remove a member or an invitation, then try again. A result marked incomplete means the account exists but setup needs attention. Save its password, then use invitations to complete access or contact support if it already appears as a member. If a network failure loses the response, check the member list before retrying; use Forgot password for credentials that were not returned. Creating an account does not verify ownership of its email or claim an existing customer profile. Team members appear in the people directory. App users appear there when Customer Identity is turned on for the app (Settings → Authentication).

Organization-managed accounts

Accounts created this way are managed by your organization. They carry a Managed tag in the Members list and in an app’s App Users list.
  • Admins can edit them. Click Edit account on the person’s row to change their picture, first and last name, or email, or to set a new password. Generate password sets a random one right away and shows it once, so copy it before closing. Setting a password signs the person out of their other sessions. Every change is recorded in the audit log.
  • They belong to one organization. A managed account can’t join or create any other organization.
  • Removing deletes them. Removing a managed member from the organization deletes the account, and the confirmation says Delete account. Deleting the organization deletes all of its managed accounts.
People who signed up themselves manage their own accounts. Their row shows View account, which opens their details read-only. A team member’s name and email also appear in the people directory, and stay in sync when they change.

Inviting a team member

Team members are the people who work inside Stardeck with you. They sign in to the dashboard and use the apps their role allows.
1

Open Members

Go to Settings → Members in your organization dashboard.
2

Invite a member

Click Invite member, enter their email address, and choose the role they should get. If you’re not sure, leave it on the default. Every organization has a “role for new members” that’s applied automatically.
3

Send

They receive an email invitation. It shows up as pending until they accept; you can revoke it from the same tab if you need to.
Whoever opens the invitation link joins, even if they sign in with Google or with a different email than the one you invited. Each invitation admits one person. Someone who is already a member keeps their current role, and the invitation stays open for the person it was meant for.
Adding a lot of people at once? Use Bulk invite to paste in several email addresses in one go.
A team invite link is a URL you share yourself, in a group chat, on a poster or as a QR code. Anyone who has the link can use it, so you don’t need their email. Create one under Settings → Team Members → Invite links → Create link:
  • Role: the organization role people get. Links can’t grant the Admin role.
  • Label: optional, to tell your links apart (for example “Bangkok store hires”).
  • Max uses: required, at least 1. Every link has a limit.
  • Expires: 1, 7, 30 or 90 days.
  • Apps: shown for an App-only role, which needs at least one app. Pick each app and its app role.
  • Require approval: on by default. Each person who opens the link waits under Pending approvals until someone clicks Approve or Reject. With it off, people join as soon as they sign in.
The full link is shown once, when you create it. Copy it then; after that the list shows only its first characters. Each link’s row shows its uses, expiry, pending count and who used it. Admins get a notification when someone uses a link. To stop a link, open its menu and click Revoke link. It stops accepting new requests at once. People who already joined through it stay members until you remove them. Creating, revoking and approving links needs the Invite Team Members (members:invite) permission. A link that assigns apps, which includes any link for an App-only role, also needs Manage Roles & Permissions (roles:manage).
Apps have their own links. An app’s Settings → App Users tab creates invite links for app users and claim links for app-only team members. Settings → Project Members creates invite links for collaborators. These are single-use by default and can be unlimited, in which case they expire within 30 days.

Which role should I pick?

Pick the closest fit from the roles your organization already has. You don’t need to understand every permission. The built-in ones: Your organization may have more roles than these. Each person has exactly one organization role, and you can change it later. For the full list, or to create a role, see Members & Roles.
Inviting team members may require a plan that supports more than one user. If your plan is single-user, you’ll see an upgrade prompt on the Members tab.

Giving a team member access to a specific app

Some roles are App-only: the person can’t open the Stardeck dashboard and only uses the apps you assign them. It’s the setup for frontline staff like cashiers or drivers. (See App-only access for how it works.)
1

Invite or find the member

Invite them with an app-only organization role (or pick an existing team member on the Members tab).
2

Open their account

Click Edit account or View account on their row. App access is at the bottom of the dialog.
3

Assign the app and a role

Add the specific app(s) they need and choose which role they hold inside each one.
They’ll be able to sign in to exactly those apps, and nothing else.

Changing a role or removing someone

All from the same Members tab:
  • Change someone’s role — pick a different role from the dropdown next to them. To make someone an admin, pick Admin.
  • Remove a team member — open the menu on their row and click Remove from organization. They lose dashboard and app access. For a managed account, removing deletes the account.
  • Change many at once — tick several members, then use Set role, Add to app or Remove. See bulk actions.

Managing team members inside a deployed app

Your organization can also build team invitations and organization-role changes into a deployed app. Stardeck still checks the actual signed-in team member’s current permissions before each action; simply being signed into the app is not enough. App users and app-only team members cannot use these controls. For most teams, linking to Settings → Members is simpler. Use an embedded screen when team administration is part of the app’s normal workflow. For how to set this up across a large team, see Team management for large organizations.

Inviting users to your deployed app

App users are the people who use your live app. They sign in to the app only, and never see Stardeck, your code, or your settings.
1

Open the app's users

In the app, go to Settings → App Users.
2

Invite a user

Add their email and choose an app role for them (for example, Admin or User).
3

Manage them later

From this tab you can change a user’s role, resend or revoke invitations, and remove access.
Don’t want to invite users one by one? Turn on self sign-up so people can register themselves. Anyone who signs up gets the app’s Default Sign-Up Role. See User Authentication to enable it.

Inviting a collaborator to help build an app

Collaborators (or Project Members) are people who help you build and manage one app inside Stardeck. They can touch its code, settings, and deploys. This is the right choice for an external developer, freelancer, or partner agency working on a single app. Invite them from the app’s Settings → Project Members.
A Project Member works on one app. If you want someone to build across all your apps, invite them as a team member with an organization role instead (see above).

Next steps

Members & Roles

Create roles and decide exactly what each one can do

User Authentication

Turn on self sign-up and choose sign-in methods for your app

Identities

Manage the customers and contacts your agents and apps work with

Publishing & Deployment

Deploy your app so people can sign in to it