Home / Docs / Team & Accounts / Inviting Your Team
Adding somebody to TelBuddy sends them an invite. They choose their own password from a link, and you never see it.
In System Manager, under Team, enter their name, email, and role, then send the invite. There is no password box.
They get an email with a link that works once and expires in seven days. Until they use it their account exists but cannot sign in.
It used to work the other way, and it had three problems.
Two people knew every password, and nothing ever forced a change. Anyone who had been given an account had a credential the person who created it also knew, indefinitely.
The browser offered to save it. Creating an account for a colleague meant your own password manager prompting to store their credentials.
And there is no safe way to get a password to somebody. Sending it by email leaves it in an inbox forever; sending it by text is worse.
An invite link has none of that. It works once, it expires, and the password exists only in their head.
The team list shows their status:
Resend invite sends a fresh link and immediately invalidates the previous one, so an old email that was forwarded to the wrong person stops working. Revoke cancels an outstanding invite without removing the account.
They use Forgot your password? on the sign-in page. They get a link that works once and expires in an hour.
Nobody, including you, can read or set another person's password. If they cannot get into their email, remove the account and invite them again on an address they can reach.
At least ten characters, and it cannot contain their email name, your company name, or an obvious word like "password".
There is no rule forcing a symbol and a digit, on purpose. Those rules reliably produce one predictable word with punctuation stuck on the end. A few unrelated words is both stronger and easier to remember.