Inviting Your Team
Invite someone to one job or the wider account, explain their access, and manage pending invitations.
Why It Matters
Hiring is a team effort. Inviting your colleagues lets you assign reviewers, coordinate interview panels, and gather structured feedback within Kit. Use shared criteria so reviewers can compare their assessments.
Inviting a Team Member
To add someone to your team:
- Navigate to your Account page
- Click Invite
- Enter the person’s name and email address
- Choose Account role for access across the account, or Job-only for one job posting
- For account access, choose a role. For job-only access, choose the job and their role on its team: Hiring manager or Team member
- Click Send Invitation
The invitee receives an email with a link to join your team. An invitation expires 30 days after it’s sent. Resending it restarts the 30 days, and you can revoke it at any time.
Inviting Someone to One Job
An account Admin can open a job posting and click Invite to this job, or choose Job-only on the account invitation form. Each invitation covers one job. Search the job picker by title, department, location, or status; closed jobs appear last and remain available for reviewing past candidates.
- Hiring manager can review candidates, move them through stages, and edit that job.
- Team member can view candidates, share notes, and submit reviews when assigned to a stage, but cannot move candidates or edit the job.
A new job-only teammate sees that job and its candidates. They cannot open other jobs, the talent pool, account-wide Hiring tools, billing, or account settings. The invitation email explains the job, role, access boundary, and expiry. Accept and open the job takes them to the posting after sign-in or signup. Their home page lists Jobs you’re on.
Already a member of the account? Kit adds them directly to the selected job without sending another invitation. Their existing product access stays in place; someone with no Hiring access gets job-only access to this job. An email with a pending invitation must be managed from the invitations list before a different invitation can be sent.
Removing a job-only teammate’s last job leaves their account membership in place with Job-only · no jobs and no access to Hiring content. An Admin can assign another job, change their Hiring level to Member for broader access, or remove their account membership.
Note
The role you pick is carried on the invitation and applied automatically when the person accepts. Account-role invitations are rechecked at that moment: if a delegated sender has lost access, or an Admin sender is no longer an Admin, the account role is dropped and the product levels are trimmed to what the sender can still grant. A job-only invitation is different. Because only an account Admin can create it, its selected job and team role remain valid until an Admin edits or revokes it, or the job is archived, even if the original sender’s access later changes.
Who Can Invite
Admins can always invite. An Admin can also grant a member the invite members capability from Settings → Team → Members; that person can then invite teammates without becoming an Admin. A delegated inviter cannot set the account role, cannot create Admins, and cannot edit existing members.
Inviting someone to a specific job is account-Admin-only. Being a Hiring manager on the job or an Admin of the Hiring product does not grant this permission.
Note
A delegated inviter can only pass on access they already hold. Each product is capped at their own level, and every product they lack is written on the invitation as “none”. If their own access is reduced before the invitee accepts, the grant is clamped down to match at acceptance time.
Team management over MCP is Admin-only. Delegated inviters send invitations from the Account page.
Account Roles
When you choose Account role on the invitation form, the selected role decides what the person can manage across the account and pre-fills their access to each product. You can fine-tune that access afterward. A job-only invitation does not apply an account-role preset.
| Role | What it grants |
|---|---|
| Admin | Full access to every product, plus billing, team management, security settings, and integrations |
| Billing Admin | Manages the Kit subscription and billing, with no access to the product modules |
| Finance | Processes candidate and researcher payouts and reviews W-8/W-9 tax documents, without access to product work |
| Security Analyst | Full access to the Security module, plus SSO and API settings and member-level access to Training and Performance |
| Recruiter | Full access to Hiring, plus member-level access to Outreach, Training, and Performance |
| Growth | Full access to Outreach, plus member-level access to Training and Performance |
| Trainer | Full access to Training, plus member-level access to Performance |
| People Lead | Full access to Performance, plus member-level access to Hiring and Training |
| Member | The default: member-level access to every product; narrow it per product where someone shouldn’t be |
Notes:
- Managing the account stays with Admins, except where an Admin hands out a piece of it. A Billing Admin manages the Kit subscription, Finance handles payout and tax-document work, a Security Analyst manages security settings (SSO and API access), and a member given the invite members capability can invite teammates.
- Finance starts with every product set to No access. Its focused workspace still reaches candidate payouts, researcher disbursements, and their tax documents. It does not expose candidate records, vulnerability reports, bounty approval, payout settings, or subscription billing.
- AI assistants follow the member’s access. Account-wide members can set up Kit for AI; members with only job-only access cannot open the integration settings. See Connecting AI Assistants.
- Roles pre-fill product access, they don’t cap it. Picking Recruiter gives Hiring admin plus member access to Outreach, Training, and Performance; picking Trainer gives Training admin and Performance. After inviting, an admin can adjust any product level for that person.
- Existing members are unaffected. Everyone keeps the role matching what they had before: account admins are Admins, everyone else is a Member.
For a full breakdown of what each role covers, see Team Roles.
Per-Product Access After Inviting
Kit has five products: Hiring, Security, Outreach, Training, and Performance. Each member holds one access level per product: No access, Member, or Admin. Hiring also offers Job-only, which limits access to jobs where the person is on the team. An account Admin sits above all of these levels and can reach everything.
After someone joins, an admin can fine-tune their access two ways:
- Whole-team matrix: Settings → Team → Modules shows one row per member and one column per product. Change any cell and it applies immediately.
- Per-member page: Settings → Team → Members, then click a person to set their role, adjust each product level, grant or revoke access to individual items, and read their full access ledger.
For the complete access model (product levels, the modules matrix, requesting access, and offboarding), see Team Access Control.
Job Roles
Hiring has job-specific roles assigned per posting. Set them when sending a job-only invitation, or manage an existing member’s assignment on the job posting edit page. Adding an existing person through Invite to this job gives them job-only Hiring access if they previously had none.
To assign someone to a job:
- Open the job posting and click Edit
- Scroll to the Hiring Team section
- Click Add Team Member
- Select a team member from the dropdown
- Choose their role: Hiring manager or Team member
- Click Save
The person who creates a job posting is automatically assigned as its first Hiring Manager.
| Job Role | Badge | Capabilities |
|---|---|---|
| Hiring Manager | Purple | Update job details, advance or reject candidates, create confidential notes, manage the job’s hiring team, cancel or complete interviews |
| Team member | Gray | View the job and its candidates, add notes, and submit reviews when assigned to a stage |
Once a team member is added to a job, their role badge is displayed on the row and cannot be changed. To switch someone’s role, remove them and re-add with the new role.
Account Admins, and anyone with Hiring set to Admin, have full access to every job automatically and don’t need to be added to a job’s team.
How Permissions Work Together
For Hiring, three layers combine to decide what each person can do: their Hiring product level, their job-team role, and any stage reviewer assignments. The most common scenarios:
Admin (or Hiring set to Admin): Full access to every job. Can create, edit, and delete any job, advance candidates, write confidential notes, and manage teams on every job. Doesn’t need to be added to any job’s team.
Hiring Member + Hiring Manager on a job: Manages that specific job’s pipeline. Can update the job, advance or reject candidates, write confidential notes, and add or remove team members on that job. Cannot create new jobs or access restricted jobs they aren’t assigned to.
Hiring Member + job team member: Can view the job and its candidates, add regular notes, and submit reviews when assigned to a stage. Cannot update the job, advance candidates, or create confidential notes.
Hiring Member, not on any job team: Can see all unrestricted jobs and their candidates, add notes, and submit reviews when assigned to a stage. Cannot access restricted jobs.
Hiring Job-only + Hiring manager on a job: Can review and advance candidates and edit that assigned job. Does not gain access to other jobs, the talent pool, account-wide Hiring settings, or team management.
Hiring Job-only + Team member on a job: Can view candidates, share notes, and submit reviews when assigned to a stage on that job. Cannot move candidates or edit the job. If the person also has access to another product, that access remains available.
Hiring set to No access: Can’t open the Hiring product. They see an access-denied screen with a Request access button.
Managing Invitations
After sending an invitation, you can manage it from the Account page:
- Pending: The invitee hasn’t accepted yet. Job-only rows name the job and team role; a Closed badge means the invitation still works for a closed job.
- Resend: Send the invitation email again if the original was missed.
- Copy Link: Copy the invitation URL to share it directly (useful if email delivery is unreliable).
- Edit: Change the invitee’s role before they accept. For job-only invitations, you can change the selected job or its team role.
If a job is archived, its pending invitation is marked invalid and cannot be copied, resent, or accepted. Edit it to choose an available job, or delete the invitation. Deleting the job permanently also revokes its pending invitations.
Over MCP, team_list_invitations includes job-only scope, the selected job and role, expiry, and destination validity. To change a job-only invitation through MCP, use team_revoke_invitation, then team_invite_member with the desired job_posting_id and job_role.
A delegated inviter sees only the invitations they sent themselves and can resend or revoke those; every other pending invitation is Admin-only.
Once accepted, the person appears in the team list with the access they were granted. Job-only members have a badge showing how many jobs they can access.
Acceptance Flow
When someone receives your invitation:
- They click the link in the invitation email
- If they’re new to Kit, they create an account with their name and password
- If they already have a Kit account, they sign in with their existing credentials
- They’re added to your team with the access you picked: an account role with its product levels, or a job-only team role
- They can immediately access the products and jobs their role allows
Team members can belong to multiple accounts (teams) in Kit. They switch between accounts using the account switcher in the navigation bar.
Assigning Team to Jobs
Hiring Member access includes every unrestricted job posting. Job-only access includes only explicitly assigned jobs, whether or not they are marked restricted. If you also need to hide a job from other Hiring members (for example, for a confidential executive search), check the Restricted checkbox in the Hiring Team section of the job posting edit form.
When a job is restricted:
- Only explicitly assigned team members can see the job and its candidates
- Admins (and Hiring admins) can always access restricted jobs
- A warning appears if you mark a job as restricted without assigning any team members
- Slack channel notifications for the job stop; the job team gets a DM for new applications; see Creating a Job Posting
Stage Reviewers
Beyond job-level access, you can assign specific team members as reviewers on individual stages. Stage reviewers must also have job-level access first, either through a job team assignment or by being an Admin.
There are two stage reviewer roles:
| Stage Role | Purpose |
|---|---|
| Lead | Primary decision-maker for the stage. Responsible for making the final call on whether a candidate advances. A job-only Team member may submit a Lead review but cannot make the pipeline decision; a Hiring manager or Admin handles it. |
| Reviewer | Standard reviewer. Evaluates candidates and submits scores and recommendations. |
Assigned reviewers:
- Receive notifications when a candidate reaches their stage
- See the application in their My Reviews section. Job-only reviewers instead use the direct link in their notification or open the candidate from their assigned job.
- Can submit structured reviews with scores and recommendations
Configure reviewer assignments on each stage’s settings page.
Permission Quick Reference
The columns below track account-wide Hiring capabilities. Admin / Hiring Admin means an account Admin or anyone whose Hiring product level is set to Admin. Job-only permissions are described above; they never include unassigned jobs. A member with Hiring set to No access can’t open Hiring.
| Action | Admin / Hiring Admin | Hiring Member + Hiring Manager | Hiring Member on Job Team | Hiring Member (no job access) |
|---|---|---|---|---|
| Create jobs | Yes | No | No | No |
| Update job details | Yes | Yes | No | No |
| Delete jobs | Yes | No | No | No |
| Advance/reject candidates | Yes | Yes | No | No |
| View job and candidates | Yes | Yes | Yes | Unrestricted only |
| Submit reviews | Yes | Yes | Yes | Unrestricted only |
| Add notes | Yes | Yes | Yes | Unrestricted only |
| Create confidential notes | Yes | Yes | No | No |
| Delete notes | Yes | No | No | No |
| Manage job team | Yes | Yes | No | No |
| Access restricted jobs | Yes | If assigned | If assigned | No |
Quick Checklist
- Choose Job-only for someone helping with one job, or Account role when they need wider product access
- Reserve Admin for people who manage the account; use Finance for payouts and tax documents, and Billing Admin for the Kit subscription
- Grant invite members to the people who onboard teammates, instead of promoting them to Admin
- After inviting, fine-tune per-product access from Settings → Team → Modules where the role’s defaults don’t fit
- Assign a Hiring Manager on each job posting to own the candidate pipeline
- Add additional team members to jobs as needed for review coverage
- Designate Lead reviewers on each review stage for clear decision-making
- Use restricted access for confidential job searches
- Share invitation links directly if email delivery is slow