Skip to main content
Aby
February 3, 2021

Admin/owner restrict authority to invite

  • February 3, 2021
  • 57 replies
  • 8867 views

Is there an option to restrict WHO can invite others to collaborate in an organization?
OR
Is there an option to completely restrict someone outside an organization to access a file, even if he is invited by someone within ? (Admin pains)

Suggestion 1 : Some options for admin to restrict/allow others to invite others.
Suggestion 2 : Some option to restrict organization level files from outside access (even with invite)
Suggestion 3 : A new “FILE_SHARE” Webhook to catch the file share event and do some workarounds to avoid this problem.

57 replies

luiscamino
New Participant
June 1, 2021

+1 Apart from the issues already mentioned, I’ll add a couple of things that not only baffle me, they are literally stopping our IT department from allowing a wide rollout of Figma at our company:

  • In the Figma Organization settings, one can define from which domains members can be created. It’s a way of capturing all users within a domain, but it also feels like a way of whitelisting a bunch of domains. However, this doesn’t prevent anybody from inviting anybody else, even with a @gmail.com address (or the address of a competitor…)

  • There is this handy possibility of setting a Team within an Organization to “secret”, meaning it is not visible or searchable by anybody other than its members. However, all members can invite anybody (again from any domain) to this team, without the Team owner knowing anything about it. How is this secret?

Look, we all get the point that accessibility is the priority for Figma. Ensuring that more and more people can join Figma without any friction. Great for design but also great for Figma. Nothing wrong with that. But at the VERY least, you could implement a notification system for Team owners/admins for every new invite. And since dreaming is free: add a way for team owners/admins to be able to either accept or reject each invite. Yes, it creates a waiting time and “friction”, but we gotta strike a balance here…

luiscamino
New Participant
June 1, 2021

+1

For anyone watching this, this is a related thread expressing similar concerns:
Admin/owner restrict authority to invite - Product Feedback - Figma Support Forum

To give you an idea of the level of workaround-ism we’ve had to establish, this is the form with which we tell everybody to request access to Figma. A very manual process that doesn’t technically prevent any of the aforementioned risks:

luiscamino
New Participant
June 1, 2021

Btw, here’s another thread with similar issues and some cool concept of how a reworked Admin dashboard could look like:

Request finer-grained permission control for organization admin - Product Feedback - Figma Support Forum

_Hal
June 2, 2021

Thanks for mention. Just spent one day to remove unintended editors and I’m really exhausted about it. My dear Figma, Please consider these.

_Hal
June 2, 2021

We also established a process for new editors and implemented a Chrome plugin to recognize unintended editors, but it can’t reduce too much work.

Justine
July 9, 2021

I’m quite baffled to learn that this essential administration feature / setting is not yet part of the organizational plan… For organizations it is basically a must to have control over who gets access. And this is not only about billing, but also about sensible data and projects which you don’t want everyone to get access to that simple.

_Hal
July 9, 2021

Sure, Figma need to consider it.

Peter_Andrews
July 13, 2021

Here is a fun little thing that can happen. A non-admin can invite an external person to your organization, they can grant themselves editor permissions, and then they can just do whatever they want to any of your files and materials without an admin ever knowing. It’s a terrible model. I’ve written feedback asking for this exact feature before. Please listen to this proposal.

ReneLopez
July 22, 2021

wait, so being in an organization plan doesn’t solve the problem of viewers being able to invite anyone from outside the organization?

We just found that any viewer can invite anyone, and thought that changing to an organization plan would solve this.

How is this not a major security issue?

ReneLopez
July 27, 2021


so… is it like this?