> ## Documentation Index
> Fetch the complete documentation index at: https://docs.omni.co/llms.txt
> Use this file to discover all available pages before exploring further.

# External users

> Give partners, contractors, and other outside users access to only the content and connections you explicitly share with them.

An external user logs in to Omni like any other user, but only has access to what you explicitly give them. External users don't inherit anything your organization grants by default — no organization-wide content access and no connection base role.

Use external users when your organization is open by default but a few users — partners, contractors, clients, or an offshore team — should only see specific dashboards or connections.

## Requirements

**Organization Admin** permissions are required to invite external users or convert existing users.

## What external users can access

Everything an external user can see or query comes from an explicit grant, made either directly to the user or to a [group](/administration/users/groups) they belong to.

| Area | Behavior |
| - | - |
| **Connections** | External users have **No Access** unless they're granted a [connection role](/administration/users/permissions) directly or through a group. |
| **Content** | External users can only access content shared with them directly or through a group. Content shared with the organization isn't visible, including in **Shared with me** and search results. |
| **Hub** | External users do not have access and will not see this option in the navigation. |
| **Personal content** | Allowed by default, so they can create their own workbooks and dashboards. Can be disabled with the **Allow personal content** setting in the user's settings. Content they authored before becoming external stays accessible to them. |
| **Deliveries** | They can receive [deliveries](/share/deliveries) that other users send them, but can't create or subscribe to schedules or alerts. |
| **Routines** | External users can't create or use [AI routines](/ai/routines), regardless of their connection role. |
| **Sharing** | User and group search in the share dialog returns no results, and they can't switch a document between personal and shared. |
| **Requesting access** | Opening content they can't access shows an access denied message instead of the [Request access](/share#requesting-document-access) form, even if the form is enabled. |
| **Organization permissions** | External users can not be granted Organization Admin permissions. |

## Inviting external users

1. Navigate to **Settings > Users**.
2. Click **Invite**.
3. In the **Email** field, enter the email addresses of the users you want to invite.
4. Select **Invite as external user**.
5. Click **Send Invitations**.

External users receive the same invitation email as other users and become external users when they accept. The invitation shows on the **External** tab of the user list until then.

After the invitation is sent, [grant them access](#grant-test-access) to the content and connections they need.

<Note>
  Invite requests accepted from the login page always create standard users. The first user in an organization can't be an external user.
</Note>

## Converting an existing user

<Note>
  This section doesn't apply to embed and [email-only](/administration/users/email-only) users.
</Note>

You can change a user between external and standard membership from their user settings page. You can also convert pending invitations.

1. Navigate to **Settings > Users**.
2. Click **Manage** next to the user.
3. In the **Organization Role** field, select the user's new membership type:
   * **External** - Convert to an external user. The user will no longer have access to content and connections granted to the organization by default and, if they were an Organization Admin, they will lose those permissions. This option will be unavailable if there is only one Organization Admin in the organization.

     If the user owns schedules or [routines](/ai/routines), you'll need to reassign or delete the schedules and routines first.
   * **Standard** - Convert to a standard user. The user will have access to content and connections granted to the organization by default.
4. Confirm the change in the dialog.

<h2 id="grant-test-access">
  Granting and testing access
</h2>

Because external users don't have access to anything by default, you'll need to explicitly grant access:

* **Connections** - Assign a connection role on the connection's **Permissions** tab. See [Defining permissions for a connection](/administration/users/permissions#defining-permissions-for-a-connection).
* **Content** - Share documents or folders with the user or with a group they belong to. See [Sharing with users and groups](/share#users-and-user-groups).

For example, to give a partner access to one dashboard, grant them a **Viewer** role on the dashboard's connection and share the dashboard with them directly.

<Tip>
  Adding external users to a [group](/administration/users/groups) makes it easier to grant the same access to several users at once.
</Tip>

### Testing an external user's access

To test the content and connection access for an external user, you can impersonate them to see exactly what they see. See [Impersonating users](/administration/users/impersonate) for more information.

## Limitations

* **[SCIM](/administration/authentication) can't be used to manage external users**, including creating them or adding them to groups. Invite and manage external users in **Settings > Users**, and add them to groups in Omni.
* Embed and [email-only](/administration/users/email-only) users can't be converted to external users.

## Next steps

* [Define connection permissions](/administration/users/permissions)
* [Share content with users and groups](/share)
* [Organize users into groups](/administration/users/groups)
* [Impersonate users](/administration/users/impersonate)
