TVTenvyrDocs
User guide

Accept an invitation

Create a local Tenvyr account, add a tenant to an existing account, and complete mandatory MFA.

Tenvyr does not offer public self-registration. A tenant owner or administrator must invite you.

Before you begin

Use the invitation only if:

  • it arrived through your organization's expected delivery channel;
  • the tenant and invited email are correct; and
  • you expected to receive Tenvyr access.

Invitation links are one-use and expire automatically. If the page reports that the link is incomplete or expired, ask the administrator to issue a new invitation. Do not forward an invitation.

Create a new account

  1. Open the invitation link in a supported browser.
  2. Confirm the read-only organization ID.
  3. Enter your full name and invited email.
  4. Create a 15–256 character password. Tenvyr rejects commonly compromised passwords.
  5. Select Create account and set up MFA.
  6. Add the displayed TOTP secret to an authenticator.
  7. Enter the current six-digit code.
  8. Save the one-use recovery codes in an approved offline location.
  9. Confirm that the codes are stored before continuing.

After sign-in, open Security and register a security key or passkey. TOTP is available for recovery and compatibility, but a user-verifying security key is preferred for privileged work.

Add a tenant to an existing account

If you are already signed in to a Tenvyr account, the invitation page offers Use this account:

  1. confirm that the displayed account belongs to you;
  2. select Use this account;
  3. complete fresh MFA for the target tenant; and
  4. confirm the new tenant appears in the tenant switcher.

This keeps one global account while creating a separate tenant membership. Tenant roles, sessions, and authorization remain tenant-bound.

Optional organization sign-in

After local account enrollment and built-in MFA, Tenvyr may offer a configured OIDC provider to link for future sign-in. Link only an identity you control. The provider's verified immutable subject is the linking key; matching email is never sufficient.

If acceptance fails

MessageAction
Invitation link is incompleteOpen the original complete link or request a replacement
Invitation expired or was usedAsk an administrator to issue a new invitation
Password rejectedUse a longer, unique passphrase that is not commonly compromised
Authenticator code rejectedCheck device time and enter the current six-digit code
Existing-account verification requiredSign in again and complete fresh MFA

On this page