Skip to main content
Who this is for: Brand administrators only. Other roles do not see Settings → User Access.
Go to Settings → User Access to manage who can sign in to your brand’s Keystone workspace. The page has three tabs:

Brand user tiers

Only administrators can change another user’s tier or remove them.

Inviting a brand user

  1. Open the Brand Users tab and click Invite.
  2. Enter their email and select a tier (Administrator, Manager, or Viewer).
  3. Click Send invite.
Pending invitations appear in the list until accepted or revoked. You can resend or revoke a pending invite at any time. Invite emails introduce Keystone, list what the person can do in their role, and link to the Getting started guide so teammates can onboard without extra hand-holding.

Inviting a rep

  1. Open the Reps tab and click Invite.
  2. Link the rep to an existing partner record or create a new one.
  3. Send the invitation.
Reps see accounts assigned to their partner. Sub-reps can be invited under an existing main rep and share the same data visibility. Their invite email links to Getting started.

Granting buyer access

  1. Open the Buyers tab.
  2. Find the customer account and select the contact to invite.
  3. Grant portal access — the buyer receives an email to set their password.
Buyers see their own account’s orders, invoices, and ordering tools. Their invite email links to the Buyer portal guide.

Removing access

Use the actions menu next to any active user to revoke access. Revoked users lose access on their next page load.
Removing a brand administrator does not automatically rotate integration credentials they configured. Review integrations after removing an admin.

Single sign-on (SSO)

Enterprise accounts can configure SAML 2.0 SSO. Contact support@keystoneb2b.io to enable SSO for your domain.
  • Settings → Assign Reps — map unassigned customers to sales reps
  • Getting started — overview of roles and navigation