External Collaborators
Invite contributors outside your organisation via magic links.
External Collaborators
External collaborators are people outside your organisation who need temporary, controlled access to specific playbook sections. This includes consultants, external incident responders, auditors, legal advisors, and other third parties who contribute to your incident response planning without being permanent members of your team.
Unlike team members, external collaborators do not need CrownSync accounts. They access the platform through magic links with TOTP multi-factor authentication, and their access is limited to the specific sections you assign to them.
Magic Link Invitations
To invite an external collaborator:
- Navigate to Admin → Collaborators
- Click Invite Collaborator
- Enter the collaborator's name and email address
- Select the playbook sections they should have access to
- Set an access expiry date (optional but recommended)
- Click Send Invitation
The collaborator receives an email containing a unique magic link. When they click the link, they are taken to a verification page where they set up TOTP multi-factor authentication before gaining access.
TOTP Multi-Factor Authentication
All external collaborators are required to set up TOTP (Time-based One-Time Password) multi-factor authentication on their first access. This is mandatory and cannot be bypassed.
The setup process works as follows:
- The collaborator clicks the magic link in their invitation email
- They are presented with a QR code to scan with an authenticator app (such as Google Authenticator, Microsoft Authenticator, or Authy)
- They enter the six-digit code from their authenticator app to verify the setup
- On subsequent visits, they enter their email address and a fresh TOTP code to authenticate
Why TOTP Is Required
External collaborators access sensitive incident response documentation without a full CrownSync account. TOTP MFA provides an additional layer of security, ensuring that even if a magic link is intercepted, the collaborator's identity must be verified through a second factor before access is granted.
Section-Level Access
External collaborators can only view and edit the specific playbook sections assigned to them. They cannot see the rest of the playbook, other playbooks, the dashboard, admin settings, or any other part of the platform.
When assigning sections, consider the principle of least privilege — grant access only to the sections the collaborator genuinely needs. You can assign multiple sections across different playbooks if required.
Section assignments can be changed at any time from the Collaborator Management page. Adding or removing section access takes effect immediately.
Time-Limited Access
When inviting an external collaborator, you can set an expiry date for their access. Once the expiry date passes, the collaborator can no longer access the platform, even with a valid TOTP code. This is particularly useful for:
- Consultants engaged for a fixed project duration
- External responders assisting with a specific incident
- Auditors who need temporary access during an assessment period
If no expiry date is set, access remains active until it is manually revoked.
Review Active Collaborators Regularly
CrownSync recommends reviewing your active external collaborators at least quarterly. Revoke access for any collaborators who no longer need it. The audit log records all collaborator access activity to help you identify inactive accounts.
Revoking Access
To revoke an external collaborator's access:
- Navigate to Admin → Collaborators
- Find the collaborator in the list
- Click Revoke Access
- Confirm the revocation
Revocation is immediate. The collaborator loses access to all assigned sections and can no longer authenticate. Their previous activity remains in the audit log. If you need to reinstate access later, you must send a new invitation.
Was this page helpful?