When using the Whitelisted or Protected policy, you configure a list of allowed email domains. Only people with email addresses matching one of these domains can auto-join (whitelisted) or request access (protected). Everyone else needs an explicit invitation.
Add or remove domains at any time from the invite policy settings. Enter a domain (e.g. acme.com) and save — anyone with an @acme.com email address can then join or request access depending on your policy. Changes take effect immediately.
You can whitelist up to 5 email domains per workspace. If you need to support more domains, consider using the Protected policy so an owner can manually approve requests from any email address.
If you need to invalidate existing invitation links, you can rotate your workspace’s invite token. This invalidates all pending invitations and generates a new token.