VISTASecurity
  • Vista Platform
  • How it works
  • Insights
  • Docs
  • Release status
  • Mailing list
Try Core
Vista Documentation
  • Editions
  • Vista Platform Platform Overview
  • Cbom
    • CBOM Artifacts
  • Features
    • Algorithm Reference
    • AI Assistant Integration (MCP)
    • Asset Approval Workflow
    • Asset Lifecycle Management
    • AWS Cloud Resource Discovery
    • Azure Cloud Resource Discovery
    • Certificate Chain Management
    • CMDB Integrations
    • CMDB Terminology Glossary
    • Compliance Framework Management
    • Crypto Risks Dashboard
    • Cryptographic Keys
    • Device Interrogation Feature
    • Discovery Feature
    • Fortinet Device Interrogation
    • Viewing Frameworks, Controls & Measurements
    • GCP Cloud Resource Discovery
    • Getting Started checklist
    • Global search (⌘K)
    • Inventory and Lenses
    • Measurement Templates
    • Inviting Members
    • Infrastructure Assets and Crypto Configurations
    • Network Spaces Feature
    • Operational Context
    • Page-local Export
    • PCAP File Ingestion
    • Remediation
    • Scopes
    • Enhanced Sensor Registration & Management Guide
    • Spreadsheet Import
    • Third-Party Systems and External Connections
    • Unified Crypto Inventory
  • Guides
    • Audit Logging User Guide
    • Cloud and Device Management Separation – Migration Guide
    • Device Auto-Discovery Troubleshooting Guide
    • Device Interrogation User Guide
    • Tenant Administrator Guide
    • Tenant User Guide
  • Operating VistaPlatform
    • Container runtime images (source of truth)
    • Platform Administrator Guide
    • Releases & Versioning
    • Service Startup and Shutdown Procedures
    • Configuration
      • Platform Integrations Configuration Guide
    • Deployment Documentation
      • Database Deployment Readiness – Sensor Management Enhancements
      • Database Migration Guide
      • Device Agent Deployment Guide
      • Managed vs In-Cluster Data Services (EKS)
      • Deployment Migration Checklist
      • Production Deployment Checklist
      • Deployment Propagation Guide
      • Vista RKE2 v1 — Customer Documentation
        • Vista — RKE2 Cluster Provisioning Guide
        • Vista Deployment Guide — RKE2 v1
        • Vista RKE2 Deployment — Pre-Flight Checklist
        • Vista Security Overview — RKE2 v1
        • Vista Support Bundle
    • Monitoring
      • Compliance Engine Event Processing Alerts
      • Compliance Log Management & Retention
      • Production Monitoring & Alerting Setup
      • System Monitoring & Alerting Guide
    • Operations
      • Notification Provider Integration Guide
    • Security
      • 🔒 Security Architecture for Cloud-Hosted Control Plane
      • Bootstrap Certificate Management
      • Certificate Management Operations Guide
      • Secrets Management Guide
    • Troubleshooting
      • Asset Approval Workflow Issues – Resolution Documentation
      • Troubleshooting Guide
      • Runbooks
        • Gateway Runbook
        • Recovery and Resume After Reboot
Vista/Docs

Inviting Members

Vista uses one invitation flow for every sign-in method. You invite a person by email and choose their role; they choose how to sign in when they accept — a password, Google, or Microsoft — based on what your organization has enabled. You don't pre-decide their method, and you never have to send anyone a long sign-in URL.

Invite someone

  1. Go to Settings → People & Access → Members.
  2. Click Invite member.
  3. Enter their email address and pick a role (you can change it later).
  4. Click Send invitation.

They receive an email with an Accept invitation link. The dialog also shows a copyable invite link — handy if your email relay is still being set up or the message is slow to arrive. Anyone with that link can accept as the invited email address, so treat it like a password.

What the invitee sees

Opening the accept link shows a page that confirms the email they're joining as, then offers the methods your organization allows:

  • Continue with Google / Continue with Microsoft — appears for each SSO provider you've configured under Security & SSO. They authenticate with that provider and land in the app; their account is created and linked automatically with the role you chose.
  • Set a password — appears unless your organization is SSO-only. They choose a password and are signed in immediately.

Either way the result is the same account, with the role from the invitation. Members can add another sign-in method later from their profile.

Manage pending invitations

Under Members, a Pending invitations list shows everyone invited but not yet joined. For each you can:

  • Resend — issues a fresh link and emails it again (the old link stops working).
  • Revoke — cancels the invitation; the link stops working.

Invitations expire after 7 days; resend to extend.

How this relates to SSO settings

  • The methods on the accept page come straight from Settings → People & Access → Security & SSO (your configured Google / Microsoft providers) and your authentication policy. Configure SSO there first if you want invitees to join with Google or Microsoft. See the Security & SSO guide.
  • Allowed email domains on a provider still apply: an invitee can only complete SSO if the identity provider returns an address in an allowed domain.
  • You do not need to create an account before someone signs in with SSO — inviting them (or, where enabled, their first SSO sign-in) creates it. Creating a separate password account for someone who will use SSO is unnecessary and is not how onboarding is meant to work.

Notes

  • Inviting an email that already belongs to a member is rejected — they already have access.
  • The invited role is applied on accept. Adjust it anytime from the member row (Change role).
← Measurement Templates Infrastructure Assets and Crypto Configurations →

View source on GitHub · Published from 470d8ee

On this page
  • Invite someone
  • What the invitee sees
  • Manage pending invitations
  • How this relates to SSO settings
  • Notes
VISTASecurity

Vista Platform is a self-hosted cryptographic system of record for continuous discovery, evaluation, action, and proof.

Vista Platform

How it works
Governance
Post-Quantum
Core, Enterprise & MSP
Try Core

Resources

About
Insights
Documentation
Release status
GitHub ↗
info@vistasecurity.io
Join the mailing list

© 2026 Lakeshore Labs LLC. Vista Security is a brand of Lakeshore Labs LLC. All rights reserved.