Project invitation restrictions and the allowlist

This article outlines how to enhance your project’s security through invitation restrictions and the allowlist feature. These settings let you control who can be invited to the project.

Set up invitation restrictions

To improve project security, restrict invitations to users with specific email domains. This ensures that only authorized users have access to the project.

🚧

Important

Only users with SSO Account Admin permissions can manage these settings.

Manage restrictions in Project settings > General > Security > Invitation settings.

Configure invitation expiration time

Set an expiration time to control invitation validity. Once the time passes, users will no longer be able to accept the invitation. Customize the expiration time to suit your security requirements, choosing between days or hours.

Expiration time limitations

  • Maximum time: 180 days
  • Minimum time: 1 hour

Enable and configure domain restrictions

Domain restrictions allow you to limit invitations to users with email addresses from specific domains.

📘

Note

This restriction does not affect users invited before its activation.

To enable domain restrictions:

  1. Activate the feature by toggling the switch.
  2. Enter up to 10 allowed domains (without the "@" symbol). For example: domain.com.

If you invite users from a domain not on the allowlist, you will get an error message.

Domain limitations

  • Allowed domains: You can allow a maximum of 10 email domains. If you reach this limit, you must remove a domain before you can add a new one.
  • Default domains: You cannot remove domains Bloomreach owns.