Bring the right people onto CoverGuard — and keep everyone else out. When invite-only signup is on, an account can only be created for an email you've invited, so the platform stays locked down for a controlled go-live.
Who this is for: CoverGuard staff (any @coverguard.io team member). Where: the admin Invitations & email page → Invitations tab (/admin/invitations). Time: ~2 min per invite.
This is an internal-staff guide. Invited users don't need it — they just click the link in their invitation email and create their account.
What invite-only signup does
While it's on, CoverGuard refuses to create an account for any email that hasn't been invited. That closes the front door: no one can self-register from the login or signup pages, and no one can slip in through "Sign in with Google" either. The only people who can create an account are:
- Invited emails — anyone a CoverGuard employee has invited (see below).
- CoverGuard staff — any validated
@coverguard.ioaddress. - Team invitees — someone invited to a paid company/team account keeps their normal "claim your seat" path.
Everyone else who tries to sign up sees a clear "CoverGuard is currently invite-only" message.
Invite a user
Someone asked for access? Work the queue, not the Slack thread. People who reach the sign-up page without an invitation can request one themselves, and every waiting request now appears in an Access requests panel at the top of this page — with their email, how long they've been waiting, the account type they picked, whether they came from the sign-up wall or a marketing link, and the property they were checking. - Approve invites them in one click. It carries their suggested account type and their property across automatically, so they land on the right starting view with that property ready as their first search. - Decline clears the request and removes it from the queue. Use these buttons rather than retyping the email into the invite form below. An invitation sent from the queue is linked to the request it answers, so we can tell how long people wait and how many go on to use the platform; one typed by hand looks identical to the invitee and tells us nothing. Requests still post to the team Slack channel as a heads-up, and the oldest wait also shows on the internal Observability page under Access control. Nobody is let in until a person here says yes.
- From the top nav, click Admin (staff-only), then open Invitations & email in the admin sidebar (
/admin/invitations) — it opens on the Invitations tab. - Enter the person's email.
- (Optional) Pick a suggested account type (home buyer, home seller, agent, mortgage, insurance broker) and add a short note — both appear in the invitation email. The account type also pre-selects their account type for them when they open the invitation link, so they have one less thing to choose. It is a head start, not a restriction: they can still pick something different, and the account is created as whatever they choose.
- Click Send invitation.
The invited person gets a branded email with a personal signup link. When they open it, the signup form is pre-filled and locked to their invited email — and pre-set to the account type you suggested, if you picked one — so they land straight on "create your account".
Manage invitations
The list shows every invitation and its state:
- Pending — invited, not yet used. You can Resend the email or Revoke it.
- Accepted — the person created their account.
- Revoked — access was withdrawn; that email can no longer sign up (unless you invite it again).
Use the search box and the status tabs to find an invitation quickly.
Turn the lock on or off
The toggle at the top of the page controls the whole platform:
- On (the go-live default) — invite-only, as described above.
- Off — anyone can register again (open signup).
Flipping it takes effect immediately, with no redeploy. Only turn it off when you intend to open signup to the public.
What it means
Every invitation you issue and every one you revoke is tracked — recorded in the activity history and the tamper-evident audit trail, attributed to you. You can see the current posture and the pending/accepted counts at a glance on the internal Observability dashboard under Access control.
If someone told us which property they were asking about, their invitation carries it. When you approve an access request, the address they typed comes along automatically — you don't need to copy it out of the Slack notification, and you shouldn't retype it, because a mistyped address is worse than none. It goes into their invitation email, and when they sign in it's waiting as their first search. You can still correct it when you issue the invitation if it's obviously wrong.
How long we keep it. A property address is removed as soon as you approve or decline the request, and automatically after 90 days if nobody has acted on it. The request itself is deleted after 24 months. That's stated in the privacy policy, and it happens on its own — you don't have to clean anything up.
Tips
- Re-inviting an email that already has a pending invitation just refreshes it and keeps the same link valid — it won't create a duplicate.
- Revoking a pending invite is the fastest way to pull back access before someone has signed up.
- A
@coverguard.ioteammate never needs an invitation — the staff domain is always allowed.
Troubleshooting
- "Email delivery is not configured" — the deployment has no mail provider set, so the invite can't be emailed. Share the signup link another way, or ask an operator to configure email.
- An invited person still sees "invite-only" — confirm they're using the exact email you invited (invitations are tied to a specific address), and that the invitation is still Pending (not revoked).
Do this next
- Review who's on the platform in Users (
/admin/users). - Watch signup posture and the invitation backlog in Platform admin & observability.