Help Center

Team access and security

Manage profiles, invitations, Team Chat, roles, permissions, sessions, MFA policy, organization security settings, and safe administrative access.

Back to Help Center
Updated September 2, 20266 min read

Key points

  • Invite users into the correct organization and give them only the permissions they need for their role.
  • MFA, session controls, roles, and organization security settings should be treated as operating controls, not one-time setup tasks.
  • Administrative changes should be made by authorized users and reviewed when teammates change responsibilities or leave the organization.

Invite teammates into the right organization

Flowtix is organization-scoped, so team membership is part of the tenant boundary. Invite users through the workspace team-management flow instead of sharing one account across multiple people.

When a user joins, verify their display profile and role before they begin handling customer data or administrative settings.

Use roles and permissions deliberately

Authentication proves who signed in, while authorization determines what that person can do. A valid user should not automatically receive billing, security, organization-management, or other privileged access.

Assign the least amount of access needed for the user to perform their job, then review permissions when responsibilities change.

Use Team Chat without replacing operational records

Team Chat is useful for internal collaboration, direct messages, group discussion, presence, and quick coordination. Important customer commitments, deal stages, tasks, and follow-up decisions should still be recorded in the relevant CRM workflow so they remain visible in operational history.

Review sessions, devices, and MFA policy

Session and device controls help organizations respond when a device is lost, a user changes roles, or access should be revoked. MFA requirements add another authentication layer for organizations that need stronger sign-in controls.

If access is revoked or a security policy changes, users should not rely on an old browser session continuing indefinitely. Re-authentication and policy enforcement are part of the expected security model.

Keep administrative access controlled

Billing, invitations, integration connections, security settings, API access, and other administrative actions should remain limited to authorized roles. Avoid sharing login credentials or copying private tokens between team members as a shortcut.

When a teammate leaves the organization, review membership, sessions, assigned work, integration ownership, and any privileged access that should be removed or transferred.

Need to continue from here?

Use the related product page for the next step, or contact Flowtix support if the workspace is not behaving as described in this current guide.