Back to library
AccessWorkflow capture pendingReal TASC screen

Add organization users and assign access

Invite administrators, managers and supervisors without confusing licensed users with connected workers.

8 minutes6 stepsCoreUAT screen captured · Production cross-check pending

Outcome

The pilot team has only the authenticated access it needs, with clear separation between licensed organization users and connected workers.

Find it in TASC

Employer PortalUsersAdd User

Before you begin

  • The person’s work email and employee or contractor type
  • Their required role and site scope
  • An approved permission profile
  • Available organization-user capacity

Actual TASC screen

Organization users and capacity

Authenticated organization users and connected Safety Passport workers are managed separately.

UAT capture
Annotated and privacy-redacted TASC Users screen showing user management, invitation and authenticated-user capacity controls.Open full-size
TASC UAT · identifying data redacted · 6 Sep 2026. Callouts were added for learning; identifying information is redacted and active training codes are hidden.
1User ManagementManage organization users, roles and permission visibility.
2Invite UserUse this only when the person needs authenticated platform access.
3User capacityConnected Safety Passport workers do not consume authenticated-user capacity.

Decisions that matter

User or connected worker?

Create an organization user only when the person must enter the employer portal. Passport-only workers do not consume user capacity.

Role

Use Org Admin, Manager or Supervisor according to responsibility—not seniority alone.

Overrides

Start with a reusable permission profile and document any person-level exception.

0 of 6 steps complete0%
x

Progress is saved on this device only.

  1. Step 1

    Choose the correct person type

    Confirm whether the person is an employee or contractor and whether they need authenticated platform access.

  2. Step 2

    Enter contact details

    Add the invited person’s email, name and contractor company when applicable.

  3. Step 3

    Choose a role

    Assign Org Admin, Manager or Supervisor based on the work the person must perform.

  4. Step 4

    Apply a permission profile

    Use a reusable profile for consistent access across modules and platform areas.

  5. Step 5

    Review exceptions

    Apply individual surface overrides only when the person genuinely differs from the profile.

  6. Step 6

    Send and verify

    Send the invitation, confirm its status and test the resulting access before assigning operational work.

Prove it worked

  • Invitation status is visible
  • The invited person can sign in
  • Only the intended sites and modules appear
  • A denied-area check proves restricted access remains restricted

Common problems and safe recovery

The invitation arrives but the person sees the wrong tools.

Review role, permission profile, individual overrides and site assignments together.

The organization is at user capacity.

Do not invite a Passport-only worker as a user. Review the intended person type and plan capacity.

What happens next

Test the new account using a synthetic task before assigning live operational responsibility.