ColleagueOne documentation

Admin & members

Manage invite-only access, member roles and organisational responsibilities.

ColleagueOne organisations are invite-only. Roles determine who can manage organisational settings and who can participate in workspace work.

Roles

  • Owner — holds the highest level of organisational responsibility, including ownership-level administration.
  • Admin — manages members and administrative configuration within the permissions granted by the product.
  • Member — participates in workspace work within organisation policy and assigned access.

Use the least-privileged role that allows a person to do their job. Avoid using owner access for routine work.

Invite a member

From the organisation’s member administration area, invite the person using their organisational email address and assign the appropriate role. Confirm that the intended identity provider and domain policy allow the sign-in method.

Review access regularly

Review owners, admins and members when a person changes team, responsibility or employment status. Remove access that is no longer required and inspect the impact on colleague ownership, automations and outstanding approvals.

Sign-in methods

ColleagueOne supports Google and Microsoft Entra sign-in, SAML and OIDC SSO, email sign-in links, and SCIM provisioning. The methods available to a member depend on organisation configuration.

Operational responsibilities

Assign clear human owners for colleagues and recurring work. A technical member role alone does not establish who is accountable for reviewing a result or approval. Document those responsibilities in the organisation’s operating process.

Security guidance

  • Keep the number of owners small and current.
  • Use organisational SSO and lifecycle management when available.
  • Investigate unexpected invitations or role changes through the audit record.
  • Do not share sign-in links or service-account credentials.

For automated lifecycle management, continue to SSO & SCIM.