Skip to main content
Browse documentation
GuideAdministrators

Manage Platform Admin team access

Invite, cancel, and remove Platform teammates through audited access workflows.

Updated 23 August 2026

Authorised Platform owners can invite another Discentik administrator to the Platform
team. Each link is valid for seven days, works once, and grants only the Platform role
selected when it was created.

Create an invitation

  1. Open Platform Admin, then Team.

  2. Select Invite.

  3. Enter the teammate's email address and choose the required Platform role.

  4. Select Create invite, then share the generated link only with that person.

The address must not already belong to a Discentik account. If an earlier pending link
for the same address expired, creating a new invitation replaces that expired pending
record. Creating the invitation and its Platform audit event is one transaction. If
the response is interrupted, retry the unchanged invitation from the page; its request
identifier prevents a second token from being created.

Accept an invitation

  1. Open the invitation and enter your name.

  2. Select Send secure verification link. A password is not created and the
    invitation is not consumed at this stage.

  3. Open the secure link sent to the invited email address.

  4. On the returned invitation page, create a new password and select Set password
    and accept invitation
    .

The returned email session, one-time link, invited email, created account, and
database-assigned Platform role are checked together. Other sessions for that account
are revoked before access is granted, then the profile, invitation consumption, and
audit record are committed together. A normal password sign-in cannot substitute for
the secure email link.

An expired or previously accepted link cannot be reused. Create a new invitation when
the seven-day window has passed. Do not change the email in an old link or forward a
link to a different person.

Cancel pending access

Open the pending invitations list from Team and cancel a link that was sent to the
wrong address or is no longer needed. Expired links disappear from the pending list;
they do not resolve to Platform team profiles later. Cancellation checks the exact
invitation version and commits with its audit event, so refresh before retrying a
version-conflict message.

Remove teammate access

Use Remove beside a teammate only after confirming the person and current Platform
role. The workflow changes the account back to an ordinary user, revokes its active
sessions, and records the removal in the Platform audit log as one transaction. It
does not delete the person's ordinary learning account or history.

You cannot remove yourself or the Platform owner through this control. Refresh before
retrying when the teammate's role changed in another session.

Transfer Platform ownership

Only the current Platform owner can transfer ownership, and the recipient must be an
active Platform admin on the same Platform team.

  1. Open Platform Admin, then Team.

  2. Select Transfer ownership beside the new owner.

  3. Confirm Send code. The code is sent to the current owner's verified email and
    expires after ten minutes.

  4. Enter the six-digit code and select Verify transfer.

The database rechecks both accounts, promotes the selected teammate, moves every
Platform teammate and pending invitation to the new owner, keeps the previous owner
as a Platform admin, revokes both owners' sessions, and records the audit event in one
transaction. If delivery fails, the pending challenge is cancelled. If the response
is interrupted after verification, retry the same code from the open form; the same
operation cannot apply the transfer twice.

Delete a Platform identity

Platform owners and teammates cannot use ordinary self-service account deletion while
they still hold Platform access. Remove a teammate through the audited workflow first;
they can then use the ordinary deletion flow as a user. Platform-owner deletion stays
blocked until ownership has been transferred through Platform Admin > Team.
After transfer, another Platform owner must remove the former owner's Platform access
before ordinary account deletion becomes available. Do not use direct database or Auth
deletion as a substitute.

Did this page help you?

Your response helps us improve this guide.