Team & Site Management
Invite your team and assign access
Invite a teammate through the CMS or BlockNinja account portal, choose the narrowest suitable role, and verify access without exposing private site data.
Goal
Invite one teammate through the correct access path, give them only the access they need, and confirm that the invitation and role are correct. This guide covers both a local CMS user and a managed BlockNinja account teammate.
Before you begin
- Use an Admin or Superadmin account for a local CMS invitation.
- Use an account Owner or Manager for an account-portal invitation.
- Confirm the recipient's approved work email and the site they should reach.
- Choose a fictional example address while practising. Never capture a real invitation address in documentation or support evidence.
Hazard: Sending an invitation is an external action. Review the email, role, and site before selecting Send Invite.
Choose the right invitation path
| Need | Where to start | Role controls |
|---|---|---|
| Access one CMS directly | CMS Users | Viewer, Admin, or Superadmin inside that CMS |
| Join the managed BlockNinja account | Account portal Team | Account role plus optional access to each site |
Do not invite the same person through both paths unless your access plan explicitly requires both identities.
Invite a local CMS user
- In the CMS, open Users.
- Select Invite User.
- Enter the person's first name, last name, and approved email address.
- Select Viewer, Admin, or Superadmin.
- Read the invitation summary before sending.

Choose a local CMS role
| Role | Use it for | Review point |
|---|---|---|
| Viewer | People who need read-only administrative visibility | Confirm they cannot make the planned content change |
| Admin | Editors and site operators doing routine CMS work | Confirm the task does not need Superadmin-only control |
| Superadmin | Trusted administrators responsible for privileged site administration | Use sparingly and verify with a second administrator |
Plugin permissions can add context to a role. Test the actual task after acceptance rather than assuming every screen behaves identically.
Invite through the account portal
- Open the BlockNinja account portal and choose Team.
- Select Invite Member.
- Enter the approved email address.
- Choose Manager when the person must invite or manage team members; otherwise choose Member for account-dashboard access.
- Under Site access (optional), choose access only for the required site.
- Review the choices, then send only when authorised.
Assign per-site access
For each site, the portal offers No access, Admin, Editor, or Viewer. Leave unrelated sites at No access. Account role and site access answer different questions: the account role controls account-dashboard responsibilities, while site access controls entry to a particular site.
After SSO, verify what the person can actually do in that CMS. Do not promise a local Viewer/Admin/Superadmin label unless the current managed-access policy has been independently checked.
Review before sending
- Email belongs to the intended person and organisation.
- Account role is no broader than required.
- Only the intended site has access.
- The site access level matches the assigned work.
- No screenshot, note, or support message exposes private members or sites.
Verify the invitation
- Confirm the new entry shows the expected pending or invited state.
- Ask the recipient to use the invitation once.
- Have them sign in through the same path you intended.
- Replay one allowed task and one task that should remain unavailable.
- Record the reviewer, date, invitation path, and verified role without recording personal data.
Change or remove access
Open the relevant user or team-member record. Change the role or per-site access only after confirming the new responsibility. Remove access promptly when it is no longer needed. An account Owner's access may be fixed; transfer ownership through the approved account process rather than trying to weaken it from a site row.
Recover from a problem
- Wrong email: revoke or remove the pending invitation, then create a new one.
- Wrong role: correct it before the person starts work and repeat the access test.
- Invitation not received: confirm spelling and the pending state before resending.
- Person reaches the portal but not the site: check the site's per-site access rather than broadening the account role.
- Local and managed identities are confused: stop, identify which sign-in route is intended, and remove the unnecessary duplicate after review.
Completion check
The task is complete when the recipient can use the intended sign-in path, perform the allowed work, cannot reach unrelated sites or privileged actions, and an independent administrator has confirmed the least-privilege choice.
Publication gate: keep this guide private until a second reviewer has replayed both invitation paths with fictional data and verified the current role labels.
Related guides
Sign in and tour the admin
Sign in to BlockNinja, learn the sidebar and header controls, search for admin destinations, open your site, and find profile or sign-out options.
Roles and access at a glance
Compare Viewer, Admin, and Superadmin access, choose the least privileged role for each task, and understand how managed SSO roles map into the CMS.
Set up a managed SSO site
Launch a provisioned BlockNinja site through SSO, confirm your mapped CMS role, and continue normal setup without using the standalone wizard.