Workspace admins can now set new workspace users to default to the Restricted member role when restricted members are enabled. The default applies consistently across direct invites, invite links, domain auto-join, SAML, SCIM, and pending invite approvals, while an explicit invite role still takes precedence.
Screenshot 2026-08-18 at 1
Where to find it:
Configure the default in workspace member permissions alongside the restricted-member setting, then use the normal invitation and membership flows (Profile picture dropdown -> Settings -> Security)
Who it helps:
Workspace admins and security teams can apply a consistent least-privilege starting role for new members across different onboarding paths.