Inviting and managing end users
Your customers use a separate login system from your builder account. Prefer invites for controlled rollouts; use Registration when self-serve signup fits the product. Still Preview as before inviting cohorts.
Most customer apps use invites and/or Project Registration.
When App Registration is on, the person who signs up becomes the workspace owner. They invite their own staff from the portal People item (not from your builder End-Users list). You still use End-Users for impersonation, MFA reset, and delete all data.
Invite flow
Workspace owner (portal)
- Sign in to the portal as the workspace owner.
- Open People (drawer More, or the profile menu in Tabs).
- Invite with email and a staff role. If the app has user profiles, fill any extra invite fields for that role. They accept the same invite link as builder-sent invites.
- Change roles, resend or revoke invites, or transfer ownership from the same page. Last seen comes from live use of this workspace. Make owner only works for an active person already in the workspace. You choose the staff role you step down to, and you stay signed in with it. The new owner may need to sign in again.
owner and admin roles are not offered in People either, because they still have full tool and data access. Pages and navigation can hide them when a role list does not include them. Only you can assign those from End-Users. Workspace owners also cannot impersonate, reset MFA, or erase records. Those stay on builder End-Users. Export user data, Delete all data, Reset MFA, Revoke session, and Reactivate user on End-Users ask the builder for a fresh authenticator code. If you have not set one up, the dialog says Authenticator required and Open Profile takes you there.
Builder (dashboard)
- Select the project that should hold their data.
- Open End-Users, send an invite with a role (plus any extra invite fields), or enable the right Registration mode under App Settings → Access → Registration.
- Accept the invite in a private window (password, any register profile fields, and End-User Platform Terms and End-User Privacy Policy).
- Confirm the portal role matches; revoke or resend from End-Users if stuck.
- To change how they appear in filters and pickers, open Edit User and set Name. Email stays the same. In Build you can also say: rename that person to their preferred name.
Invite alex@example.com as a participant in this project. They should only see Today and check-in.
Enable Project Registration so people can join existing projects themselves. Do not turn on App Registration (new project per signup) unless we want multi-tenant onboarding.Self-register and invite accept both require agreeing to the End-User Platform Terms and the End-User Privacy Policy. Workspace owners manage access from portal People. Builders manage access and revoke sessions from End-Users. If a role must finish intake, a waiver, or another form after login, configure Required steps. That is separate from public intake links. The portal does not tell a visitor whether an email is already registered. Signup always returns the same generic success message for a new address, an existing account, or a pending invite. Then they sign in, or use their invite link. A second signup with an existing address also sends a reminder email to that account. People who self-register (App Registration or Project Registration) must verify their email before they can sign in. After they join, the portal shows Check your email to verify your address. If they try to sign in first, they see Verify your email to sign in and can use Resend verification email. The link lasts 24 hours. A used or expired link shows Verification link expired; they request a new one from the sign-in page. Invited people skip this: accepting the invite proves the mailbox. If someone already self-registered with that email and never verified, accepting the invite lets them set a password and join. Invite links last 7 days by default and never more than 30 days. Under Pending invites an unused invite past its expiry shows as Expired, and Resend sends a fresh link. If a project does not allow public join, the portal login page still shows a generic Sign in to your account form so existing members can sign in. It does not show the project name or a Join project link. Guests use an invite link instead.
Remove from a project vs delete all data
These are different actions:
If you remove someone from their last project, they leave the In this project list and show under No access for that project only. Other projects do not list them. Their user page still opens from this project. When that remove is their last project, the confirm also offers Delete all data instead.
Delete all data only removes the account when the report shows the erase finished. If a table uses an unusual column name, the report lists it under needs a column mark. In Build, ask to mark that column as this person’s records (or to skip the table if it is not theirs), then try again.
Audit history and billing usage stay (the person is unlinked from usage). Usage signals stay as empty placeholders so the app can keep its improvement history without the person’s words.
If an invite or portal login is stuck and you cannot fix it in the UI, email support@genieforge.ai.

