The order to set up sign-in, roles, members, branding and security when you bring a team onto Flowsign.
This guide is for the admin setting Flowsign up for a whole organisation. Each step builds on the one before it, so working through them in order saves you from inviting people twice or re-assigning roles later. Every step links to the full guide for that settings page.
Members, one of the settings pages you'll work through.
Steps marked Enterprise or Business need that plan. On a lower plan, skip them; the rest of the order still holds.
1
Check your company details and plan
In Company, set the organisation Name. It appears across Flowsign and on every email your recipients receive.In Billing, confirm your plan and set the Billing email for receipts and invoices. Check the plan before going further: single sign-on, user provisioning, extra workspaces, API keys, webhooks and custom fields need Enterprise, and branding needs Business or higher. See flowsign.app/pricing for what each plan includes. Your plan’s seat limit also caps how many members you can invite or provision.
2
Add your branding (Business, optional)
In Branding, upload your logo and pick a brand colour, then check the preview email. It’s worth doing now, before anyone joins: invitation emails carry your branding, and each member’s welcome screen shows your logo the first time they sign in. You can add it later, but people who have already joined won’t see it there. It also brands every email your recipients get.
3
Verify your email domains (Enterprise)
Under Verified domains in Organisation security, add each domain your people sign in with, such as yourcompany.com, and verify it. Single sign-on can’t be turned on until at least one domain is verified.
4
Turn on single sign-on (Enterprise)
If your organisation uses an identity provider, turn on Enable SAML SSO under Single Sign-On (SAML).Test a sign-in with a member account on a verified domain before you go further. Once it works, turn on Require SSO so members on your verified domains can only sign in through your identity provider.
Owners can still sign in with their password when Require SSO is on, so you can’t lock yourself out if your identity provider is unavailable.
5
Create your workspaces
If you split work by office, region or team, create a workspace for each in Workspaces. Each workspace has its own packages, templates, contacts and members. Extra workspaces need the Enterprise plan.Do this before inviting anyone: the invite dialog asks which workspace each person joins.
6
Set up roles and permissions
Review the system permission profiles in Roles & Permissions. Where none fits, clone the closest one into a custom profile and adjust it.As with workspaces, do this before inviting anyone, because every invitation is sent with a permission profile.
7
Bring your people in
Choose one way to add members:
User provisioning (Enterprise). Generate a SCIM token under User provisioning (SCIM) and paste it into your identity provider. It then adds, updates and deactivates members for you. People it adds, and people who first sign in through single sign-on, join the default workspace with the Viewer profile. See Moving members to another workspace below. Flowsign doesn’t email people your identity provider adds, so let them know yourself and include your Flowsign sign-in link.
Invitations. In Members, use Invite member and choose each person’s workspace and permission profile. Revoke an invitation from Pending invitations if it went to the wrong person.
The Invite member dialog, with workspace and permission profile to choose.
Either way, each member counts towards your seat limit. Make a trusted colleague an owner too, so you are not the only one who can manage settings.
Signing groups are for letting any one member of the group complete a recipient’s step, for example a shared legal or HR inbox. You can set them up now; addressing a package to one is not available yet.
Session timeout: how long members stay signed in when idle, and at most.
IP allowlist: the networks members and API keys may connect from. It applies to API keys and user provisioning too, so include the addresses of any servers that call the API and of your identity provider.
Data retention: how long completed documents are kept before they are permanently deleted.
10
Build your templates
Turn the documents your team sends often into templates, with roles, fields, reminders and expiry. See Building a workflow. If you plan to use custom fields (Enterprise), define them first so your templates can use them.
Point each member to My account to set their signature and initials, and turn on two-factor authentication if they sign in with a password. They choose which events reach them in Notifications.
Single sign-on and user provisioning apply to the whole organisation, so everyone they bring in starts in the default workspace. To put someone in a different workspace, add them there and then remove them from the default. Only owners can do this.
1
Add them to the new workspace
In Members, use Invite member, enter their email, and pick the new Workspace and the Permission profile they should have there. Because they’re already in your organisation, they’re added straight away and no email is sent.
2
Remove them from the default workspace
Switch to the default workspace, open Members, and choose Remove from their actions menu. This only takes away their access to the default workspace.
Always add first, then remove. Removing someone from their only workspace deletes their account.
Permission profiles belong to each workspace, so someone can be a Viewer in one workspace and a Sender in another. Changes from your identity provider never put people back in the default workspace or reset a profile you’ve set.