---
title: "Inviting Users"
source: /gcxone/platform-fundamentals/inviting-users
locale: en
updated: 2026-09-13
---
## **What Inviting Users Does**

Onboarding new team members in GCXONE is handled through an automated email workflow.

Only users with Admin or Super Admin roles can invite new users.

## **Why It Matters**

A secure and structured invitation process ensures no user accesses the platform without an assigned role — preventing unauthorized access and blocked login screens from day one.

## **How It Works**

Inviting a user creates an account tied to a tenant, with a required Genesis Role and GCXONE Role that together decide what the user can access — a user invited without a role assigned lands on a blocked screen the moment they log in.

What happens next depends on whether the invited address already has an NXGEN account: a brand-new address is asked to verify itself and set a password before it can sign in, while an address that already has an NXGEN account (for example, an existing user added to a second tenant) is simply granted access and signs in with the password it already has.

In both cases, the user's status in the User List shows **Active** immediately after the invite is sent, even before a brand-new user has clicked either verification link. Manage the user afterward via the Actions (⋮) menu: **Edit User / Edit User Entities / Remove User.**

For the full invite form, every field, and the exact email copy, refer to [User Management](/gcxone/admin-guide/user-management).

### Multi-Organization Access

Users invited to multiple tenants use the same email address.

- **Single Identity** — They only need one password across all organizations.
- **Tenant Selection** — Upon login, they are prompted to choose which organization to access for that session.
- **Switching** — They can switch between tenants anytime via **Settings → Switch Tenant.**

Service provider and event provider information is resolved from the selected tenant context.

## **Real-World Use Cases**

- A new operator joins the team — admin invites them, assigns the Operator role, and they receive the email verification and password setup emails.
- A service provider manages multiple tenants — the same user is invited to three organizations and uses one password to access all of them, selecting the tenant at login.
- An existing user is added to a second tenant — they get a single "Access Granted" email and can log in immediately with their existing password.

## **Best Practices**

- Always assign a role before clicking Send Invitation — a user with no role lands on a blocked screen at first login.
- Set the Session Timeout based on the operator's environment — shorter for shared workstations, longer for dedicated monitoring stations.
- Ask users to check their Spam or Junk folder if they don't receive the invitation within a few minutes.

## **Additional Details**

### Troubleshooting

**Email Not Received** Ask the user to check their Spam or Junk folder for mail from `nxgen.io` or `@nxgen.io`.