Help center · 2 min read
Team and security
Invitations, single session, expiration and workspace responsibilities.
Team and security
The owner manages members in Administration. Invitations do not share a password; each person creates their own credentials.
Sign in with Google
After the owner invites your email, you can choose Sign in with Google and use the invited account. The Google account must be exactly the same as the invitation; authenticating another account does not unlock the workspace. PostemFlow automatically applies the start date, validity and status set by the owner.
Members
- Invite with a professional email.
- Choose the role and, if needed, an expiration date.
- Send the secure link through a private channel.
- Suspend or revoke access that should not continue.
The owner remains the workspace reference. Team users cannot access administration, and revocation preserves history.
Single session and inactivity
PostemFlow keeps one session identifier per user. A new login replaces the previous one. Without activity, the session expires after the configured default (30 minutes unless SESSIONIDLETIMEOUT_MINUTES is set); the user is sent to login again.
Private data
Each person should see only the workspace and clients released to them. A portal visitor sees content approved for them, but not internal notes, another client's data or administrative information.
Review access whenever you invite someone new: confirm the role, clients they need and access end date. Never share your password or someone else's.
If something seems wrong
Revoke shared links, suspend the affected member and alert the workspace owner. Keep messages and activity history so the situation can be reviewed.
