How do workspace invitations work?
Join the intended workspace, verify its invited email and keep sharing choices separate.
API 1.14.0 adds email sign-in for corporate and merchant workspaces. Email delivery, invited-email verification and explicit acceptance are separate steps; an email alone does not grant workspace access.
Who can invite whom?
| Inviter | Can invite |
|---|---|
| Platform admin | Initial corporate or merchant owner through its platform directory, using the intended owner’s email. |
| Corporate owner | HR administrators or ordinary employees (member). |
| Corporate HR administrator | Ordinary employees only. |
| Merchant owner | Merchant staff only. |
Team invitations cannot grant ownership or promote an already active member. There is no automatic join by company email domain. Each invitation expires after seven days. See Corporate workspaces and Merchant administration.
How do I send a team invitation?
Open Invitations, enter the teammate's email and choose the role. Select Review invitation, check the address and workspace, then Send invitation. Sending creates the invitation and asks the email service to send it. It does not create membership. If email availability cannot be confirmed, sending is disabled; existing invitations can still be revoked.
The list separates invitation state—pending, accepted, revoked or expired—from email state. It currently shows the latest 100 invitations. Use Refresh status after an uncertain response before deciding to replace anything.
| Email state | Meaning and next action |
|---|---|
| Not sent | Invitation exists without a confirmed send attempt. |
| Sending | Attempt is in progress; refresh before repeating. An unresolved old attempt is shown as unknown. |
| Accepted by email service | Provider accepted the message. This is not inbox delivery, verified email ownership or accepted membership. |
| Send failed | The attempt failed definitely. Review the address and status before sending a replacement. |
| Unknown / delivery unconfirmed | The message may have been accepted. Check status and the intended recipient before replacing it; do not assume failure. |
Review resend sends a replacement with a new link and invalidates the previous unused link—even if the replacement email fails. The original delivery outcome stays recorded. Accepted/revoked invitations are not resent from this action; a new invitation is needed where appropriate. Revoke disables the unused link without sending a replacement. Merchant owners can receive a reviewed email invitation or a privately shared link; both require proof of the invited email.
Can I invite several employees at once?
Corporate owners and HR can open Invite multiple employees, paste one email per line and choose Review recipients. Review accepts up to 20 distinct addresses, removing duplicate addresses and extra spaces. Check every recipient and the selected workspace before sending. The list invites ordinary employees only; use the individual invitation flow for an HR role where your permissions allow it. CSV file import is not supported.
The reviewed list uses the existing email-invitation endpoint sequentially. Its 10 requests per minute limit and other email budgets still apply: a 20-person list may stop before everyone is sent an invitation. Keep the page open and review each result. Stop after current lets the current attempt finish before stopping.
An error, uncertain outcome, rate limit, loss of access or connection stops further sends. No item is retried automatically, and no background bulk job keeps sending after you leave. An attempt already in progress may still finish. An uncertain item is not treated as unsent: check the invitation list and intended recipient before replacing it. After any displayed cooldown, choose Review unsent, check the remaining addresses and explicitly continue.
Can I update an invitation's contact email?
For an initial corporate- or merchant-owner invitation, the platform administrator can edit the pending prospect's contact after revoking any current unused invitation, then review the new recipient before sending. Resending to the same intended owner uses Resend invitation and replaces the old unused link.
After the company is active, Workspace settings allows only its owner to edit the company and business-contact display names after recent email sign-in; HR can read them. Conflicting versions or a changed account/workspace require a refresh and new review. Contact email stays read-only. Active-company contact-email changes and ownership transfers are not implemented, and an invitation cannot transfer ownership or change a login identity. See Corporate workspaces.
How do I sign in or create a client account?
Use the Corporate portal for company work or the Merchant portal for merchant work. Each has Password and Email code sign-in with a separate session. Sign-in alone grants no company or merchant role.
For your first visit, open your invitation and use Email code with the invited address. Enter the six-digit code from your inbox to verify it and create your account. New email accounts require a valid, matching invitation. Returning users with a verified email can use either available sign-in method. You may continue with email codes or choose a password through the account flow. Passwords must contain 12–128 characters.
Login codes expire after five minutes. Wait 60 seconds before requesting another and use the newest code. Failed attempts and email sends are limited. If a request times out, wait and check your inbox; the portal does not keep sending in the background.
Platform administrators use their separate email and password entry. Email-code login and self-service password recovery do not apply to platform-admin accounts.
What if I forgot my password?
Choose Forgot password?, enter your verified account email and request a reset code. Enter the code and a new password, then return to sign-in. A successful reset ends your existing sessions, including sessions on other devices. A reset request alone changes nothing. An expired, already-used or incorrect code cannot reset the password; request a new one after the displayed wait.
Accounts without a verified email need support to establish the correct identity first. The portal does not merge an existing phone account with a new email account. If you already use MedBuk on your phone and need that same account connected, ask support before creating a separate account. Platform-admin password recovery is handled by an authorized operator.
How do I accept an invitation?
- Open the personal link and sign in with your email. Use the invitation’s address for a new account; do not forward its private link or share its code.
- Review the workspace, role and expiry. Corporate owners/HR and merchant owners/staff need an email-password or email-code sign-in from the last five minutes.
- A verified matching login email satisfies the invitation’s email check. If your existing account uses another email, the separate Send email code action proves the invited inbox for this invitation only; it does not change your login identity.
- Select Accept invitation, then open your workspace. Signing in, receiving an email or verifying a code does not accept membership automatically.
Ordinary employees may also accept from an existing mobile phone session after proving the invited email. This does not grant HR access. Legacy phone-bound merchant links must be replaced by the platform administrator with a new email invitation.
The separate invited-email proof code lasts ten minutes, allows five attempts, and has a 60-second resend wait with at most five sends per hour for the account and invitation. It is different from the five-minute login/reset code. Proof is tied to the signed-in account and exact invitation. If you switch accounts, reopen the link and start again. An expired, revoked or replaced link cannot be rescued with an old code.
Does joining share my health records?
No. Membership, optional usage analytics, social visibility and each medical-leave submission are separate choices. The roster contains membership/contact details, not health readings or individual consent status. Corporate analytics show membership and invitation operations. The MC summary permits only corporate owners/HR with recent email sign-in to view already-submitted request counts and pending/approved calendar days in their own workspace. Platform reports cannot read these counts; health participation remains unavailable. See Analytics.
In the 1.13.0 medical-leave flow, storing an optional certificate photo requires its own consent; submitting it requires separate consent to share that photo with the selected employer. Draft photos stay private. Further HR viewing stops after withdrawal or loss of the relevant workspace access, and erasure or expiry also removes access. Photos are encrypted for up to 90 days, are limited to JPEG/PNG input up to 2 MiB and 20 unexpired photos per account, and are not sent to hosted AI. PDFs and certificate authenticity checks are not supported. Mobile changes still require a new build and physical-device checks. See Medical-leave requests.
How do I switch workspace or remove access?
Use the workspace selector and Switch workspace. Your current role controls which pages you can open; ordinary employees can view memberships without HR access.
The Members → Remove access flow lets a merchant owner remove staff, a corporate owner remove HR/employees, and corporate HR remove employees. Review the person and company, then confirm. The flow protects every owner and prevents self-removal; ownership transfer and general role promotion are not included.
Removal ends the membership, clears its sharing choice and active workspace session context, and revokes unused invitations for that membership email in that company. It does not delete the account or health records. Other company memberships remain separate. Rejoining needs a new invitation and does not restore sharing consent. If the member rejoined or changed while you were reviewing removal, refresh and review again. A lost response requires checking the roster, not blindly repeating removal.
Where are invitation emails processed?
Workspace emails use MedBuk+ at invitations@cenvora.dev, with Resend sending from Tokyo. Resend states that sending region controls routing, while account data, including email metadata/logs/API records, is stored in the United States. See Resend's region disclosure.
Emails contain only the workspace invitation or its verification code. They never include medical records, leave notes, MC/PDF documents or attachments. Provider acceptance is not proof of inbox delivery or completed onboarding. Do not forward a personal invitation link or share a verification code.