Skip to content
shuffl

Searches the public product guides only. Nothing from a workspace is read, and questions are not saved.

← All guides

Invite and enable employees

Invite people or let them join, check they arrived as the right person, and enable employee access.

Workspace administrators and invited employees

Read as MarkdownAll guides as textAgent documentation index

Have your agent do thisPaste the prompt into Claude Code, Cursor or another agent. It follows this guide over MCP and asks before it changes anything others will see.Show the prompt
Help me with "Invite and enable employees" in my Shuffl workspace.

1. Read the guide: https://shuffl-rebuild.vercel.app/docs/markdown/employee-access
2. Add Shuffl's MCP server: https://shuffl-rebuild.vercel.app/api/mcp
   Claude Code: claude mcp add --transport http shuffl https://shuffl-rebuild.vercel.app/api/mcp
   When the browser opens, choose my workspace and allow the access the guide needs.
3. Work through the steps in order: Send and accept an invitation; Enable access for the right person. Do what you can over MCP and tell me which steps only I can do in the browser or in Slack.

Show me what you will change and who it affects, and wait for my yes before publishing, inviting or sending anything.

App links open your signed-in workspace. Check the selected workspace before making changes.

How people get in

People arrive four ways: connecting Slack imports the Slack workspace, a directory sync or SCIM provisioning brings them from your identity provider or HR system, a verified email domain lets anyone with that work email join, and Invite or Add person adds people yourself.

App access on each row says where someone stands: Active, Access pending, Invited or Not invited. A Not invited row has its own Invite button, and Invite everyone sends an invitation to everyone in the directory with an email and no account yet.

Someone who accepts an invitation or joins with a verified email domain gets access straight away. Everyone else waits under Members awaiting access until an administrator enables them, unless a directory policy grants access.

The People page in Manage for Northwind Traders: a searchable table of people with their title, team, manager and access state, and Invite and Add person buttons in the header.
Manage → People holds everyone, whether they came from Slack, an invitation, a directory sync or were added by hand.

Send and accept an invitation

  1. Administrator: in Manage, open People and choose Invite. Paste one or more work emails, or add people from the directory, choose Employee or Administrator and select Send invitation. After a single invitation, Copy invite link shares the same link without an email. Pending invitations lists open ones to copy or cancel.
  2. To invite everyone at once, choose Invite everyone on People. It invites, as employees, everyone in the directory with an email and no account or pending invitation. Running it again skips anyone already invited.
  3. Employee: follow the invitation link, sign in or create an account with the invited email, and verify it. Choose Accept invitation.
  4. The invitation page says whether the link is ready, expired, sent to a different account or already accepted.
  5. Accepting joins the company and the workspace named in the invitation, adds you to People and turns your access on. It does not join other workspaces. If an administrator suspended or denied access earlier, you see Your access is pending, with a Check again button.
The Invite people dialog over the People page: an Emails box for one or several addresses, an Add from the directory search, a Role choice between Employee and Administrator and a Send invitation button.
An invitation carries the role. Invited people get access when they accept.
  1. Administrator: open People. Members awaiting access lists accounts that joined but are not enabled. Choose Review access. Shuffl links the account to the person with the same work email, or offers Create employee profile when there is none. If two people share the email, pick the right one.
  2. To move an account to a different person, open the person, expand Connected accounts, choose Disconnect app, then open the right person and choose Link app account.
  3. Expand Employment and access, set Employee access to enabled, enter a reason and choose Save access. Slack members waiting for access can be enabled several at a time with Enable access for N people.
  4. Employee: reopen the workspace and try Chat. A Slack account is linked separately from the app account; once both are linked, a chat started in Slack shows in your web history.

Let people at your company join by email domain

In Company settings → Email domains, choose Add a domain, enter it and add the DNS record Shuffl shows at your registrar. Choose Check DNS record; the domain reads Verified once it resolves. Anyone who signs in with a verified address on that domain then joins the company and its default workspace with access, without an invitation. Remove a domain to stop new joins.

Provision people from your directory

People → Sync lists every source that feeds People. Google Workspace, JumpCloud, BambooHR, Rippling, HiBob, Personio, Deel and Workday connect with a key or a sign-in and are read daily, or when the provider sends a change. Shuffl never writes back.

Company settings → Directory provisioning takes a SCIM 2.0 connection from Okta, Microsoft Entra ID, OneLogin, JumpCloud or another provider. Choose New SCIM connection, copy the base URL and token into your identity provider, and assign the people or groups that belong in Shuffl. Tokens expire after 90 days, so rotate them before then.

Under Who gets workspace access choose Everyone assigned to this app or Selected groups only. Newly provisioned people enter the company’s default workspace. Until you choose an access policy, they arrive with pending access. Changing the default does not move people already provisioned into another workspace. Removing someone in your identity provider takes effect at once; restoring them does not undo a manual suspension.

Sign in with your identity provider

In Company settings → Single sign-on, choose Add connection for a verified domain and pick SAML or OpenID Connect. The dialog has steps for JumpCloud, Okta, Microsoft Entra ID, Google Workspace, Rippling, OneLogin and any other provider, and shows the values they ask for: redirect URI, ACS URL, entity ID and metadata URL. SAML assertions must be signed with SHA-256.

Single sign-on proves who someone is; People still decides who gets in. It admits people to the company’s default workspace only when that workspace’s People directory lists exactly one person with the same email and enabled access. Email and password sign-in keeps working while you test.

Everyone can also add a passkey or an authenticator app under Settings → Account, whichever way they sign in.

Recover invitation or access problems

An expired or cancelled invitation needs a new one. An administrator who sees You’re not in People yet can choose Add me to People. Someone who signed up with a personal email is a different account: invite the work email or link the account they have. Suspended usually means a deactivated Slack account or ended employment in People. If access cannot be enabled, the access card says why.