Bring the right people onto CoverGuard — and keep everyone else out. When invite-only signup is on, an account can only be created for an email you've invited, so the platform stays locked down for a controlled go-live.
Who this is for: CoverGuard staff (any @coverguard.io team member). Where: the admin Invitations & email page → Invitations tab (/admin/invitations). Time: ~2 min per invite.
This is an internal-staff guide. Invited users don't need it — they just click the link in their invitation email and create their account.
What invite-only signup does
While it's on, CoverGuard refuses to create an account for any email that hasn't been invited. That closes the front door: no one can self-register from the login or signup pages, and no one can slip in through "Sign in with Google" either. The only people who can create an account are:
- Invited emails — anyone a CoverGuard employee has invited (see below).
- CoverGuard staff — any validated
@coverguard.ioaddress. - Team invitees — someone invited to a paid company/team account keeps their normal "claim your seat" path.
Everyone else who tries to sign up sees a clear "CoverGuard is currently invite-only" message.
Invite a user
- From the top nav, click Admin (staff-only), then open Invitations & email in the admin sidebar (
/admin/invitations) — it opens on the Invitations tab. - Enter the person's email.
- (Optional) Pick a suggested account type (home buyer, agent, mortgage, insurance broker) and add a short note — both appear in the invitation email.
- Click Send invitation.
The invited person gets a branded email with a personal signup link. When they open it, the signup form is pre-filled and locked to their invited email, so they land straight on "create your account".
Manage invitations
The list shows every invitation and its state:
- Pending — invited, not yet used. You can Resend the email or Revoke it.
- Accepted — the person created their account.
- Revoked — access was withdrawn; that email can no longer sign up (unless you invite it again).
Use the search box and the status tabs to find an invitation quickly.
Turn the lock on or off
The toggle at the top of the page controls the whole platform:
- On (the go-live default) — invite-only, as described above.
- Off — anyone can register again (open signup).
Flipping it takes effect immediately, with no redeploy. Only turn it off when you intend to open signup to the public.
What it means
Every invitation you issue and every one you revoke is tracked — recorded in the activity history and the tamper-evident audit trail, attributed to you. You can see the current posture and the pending/accepted counts at a glance on the internal Observability dashboard under Access control.
Tips
- Re-inviting an email that already has a pending invitation just refreshes it and keeps the same link valid — it won't create a duplicate.
- Revoking a pending invite is the fastest way to pull back access before someone has signed up.
- A
@coverguard.ioteammate never needs an invitation — the staff domain is always allowed.
Troubleshooting
- "Email delivery is not configured" — the deployment has no mail provider set, so the invite can't be emailed. Share the signup link another way, or ask an operator to configure email.
- An invited person still sees "invite-only" — confirm they're using the exact email you invited (invitations are tied to a specific address), and that the invitation is still Pending (not revoked).
Do this next
- Review who's on the platform in Users (
/admin/users). - Watch signup posture and the invitation backlog in Platform admin & observability.