read thedocs.

[ docs // guides & reference ]

Connector setup guides, tool references, auth flows, and platform concepts — everything you need to run StackJack, in one place.

34 connectors documented // 6,712 tools referenced // setup, auth & platform guides

No pages match that search. Clear it

← All documentation

Approving self-registered members

Sometimes a coworker joins your team without an invite: they sign in to an AI assistant (or the portal) with their company account, and StackJack automatically adds them to your team in a pending-approval state. They're connected but can't do anything useful until an admin approves them. This page shows exactly how that approval works — the key is the Edit Tools button.

How someone ends up pending

When a person in your identity organization signs in through an AI assistant's "Sign in with StackJack" flow without ever being invited, StackJack creates a team membership for them automatically — as a Member with essentially no tools. Their AI assistant connects successfully, but it can only call StackJack's built-in status tools (things like session info, tool listings, and health checks) — none of your connector tools.

What the pending person sees

  • In their AI assistant: the connection works, but connector tools are missing. If they (or their agent) call stackjack_session_info, the response says their status is pending approval and tells them to ask their admin to approve them on the portal Team page.
  • In the portal: every page shows an "Awaiting Approval" notice (support code SJ-ACCESS-AWAITING-APPROVAL) asking them to have their administrator approve their account.

The wording differs slightly between the two surfaces ("accept you to the team" vs. "approve your account") — both mean the same thing, and the action you take is the one below.

How to approve them (Edit Tools)

There is no button labeled "Approve." Approval = assigning tools:

  1. In the left sidebar, select Team.
  2. Find the new person in the Active Members list. Pending members look like ordinary rows: a Member badge, a green Active dot, and a tool label reading "1 tools" — that "1 tool" is the internal pending marker, and it's your cue.
  3. Select Edit Tools on their row.
  4. Select the tools their AI assistant should have. Selecting everything saves as "All tools" (no restriction).
  5. Select Save.

That's the entire approval. Access takes effect on their agent's very next request — they do not need to sign in again or reconnect anything. Their portal view switches from "Awaiting Approval" to normal on their next page load.

Things to know in the Edit Tools dialog

  • The dialog may open looking empty — the internal pending marker isn't a selectable tool, so nothing appears checked. That's normal; just select the tools you want.
  • The Save button may read "Save (1 tools)" before you select anything. That count is cosmetic.
  • Saving without selecting anything keeps them pending. Using the Clear preset and saving moves them to a "No Tools Assigned" state instead — still no access. To approve, you must actually select tools.

Other ways to grant access

  • Make Co-owner (owner-only) approves them implicitly — co-owners always have all tools and full management access. Use deliberately; see Ownership.
  • Re-inviting them from the Team page works, but the invite's tool grant only applies at their next sign-inEdit Tools is immediate and is the recommended path.
  • Their role stays Member after approval. Promote to Administrator separately if needed (Managing members).

How to deny them

If the person shouldn't be on your team at all, select Revoke Access on their row and confirm. This deactivates the membership and revokes every access path — their AI-assistant credentials, sign-in authorizations, and any per-user connector credentials — effective on their next request.

Notes for accuracy

  • The Active Members card's description ("members who have accepted their invite") is slightly off for these rows — self-registered members never had an invite. They still belong in this list.
  • Only genuinely new, signed-in coworkers land in pending. A previously deactivated member who tries to reconnect is denied outright (they need you to reactivate or re-invite them), and someone with no connection to your organization can't self-register at all.