Skip to main content

Manage guest administrators

Invite a guest administrator to manage compliance on your behalf, or remove access when it’s no longer needed.

⚠️ Select your experience

The steps to manage guest administrators depend on your interface version. Select a link to skip to the instructions for your version.

Customers who joined Drata on or after Feb 24, 2026 are automatically on the New Experience.

Instructions for the New Experience ⬇️

When to use guest administrators

Invite a guest administrator if you work with a:

  • Managed Security Service Provider (MSSP)

  • Virtual CISO (vCISO)

  • Centralized security/compliance team supporting your workspace

Prerequisites

  • Only users with the Admin role can invite or remove guest administrators.

  • Guest administrators have full access to the Drata application, equivalent to an Admin.

  • For security reasons, you can invite guest administrators only from approved email domains.

  • Personal email addresses aren't supported for guest administrator invitations.

  • To approve a new email domain, contact the Drata Support team.

  • Guest administrators must use a work email address on an approved domain that is different from your Drata tenant’s domain.

When access becomes active

Getting a new domain approved

Before you can invite a guest administrator, their email domain must be approved by Drata. This is a one-time step per domain — once a domain is approved, any future guests from that domain can be invited without repeating it.

How domain approval works

  1. Contact the Drata Support Team and provide the email domain you want to approve (for example, partnerfirm.com).

  2. Drata reviews and adds the domain on the backend — this typically takes 1 business day.

  3. Once approved, you'll be able to invite guests from that domain using the steps below.

Domain approval is required before you send an invitation — you cannot invite a guest admin from an unapproved domain, and the invitation will fail if you try. Plan ahead if you need access set up by a specific date.

What to include when requesting approval

  • The email domain to approve (e.g. partnerfirm.com)

  • The name of your organization and the guest's company or role

  • The email address(es) of the guest(s) you plan to invite

Personal email addresses (Gmail, Outlook.com, Yahoo, etc.) are not supported and cannot be approved. Guests must use a work email on a company domain.

After you send an invitation, the guest administrator may not have access immediately. Invitations are processed during a scheduled data sync, and access can take up to 1 hour after the invite is accepted.

Invite a guest administrator

  1. Go to Settings → Organization → Role administration page.

  2. Select the Guest tab, then select the Invite guest button.

    displays role admin page with invite guest button being selected

  3. Enter the guest administrator's work email address.

  4. Select Invite.

  5. Confirm the invitation when prompted.

What happens next

  • The guest administrator receives an email invitation.

  • They must accept the invitation to complete setup.

  • Until they accept, their status appears as Pending.

Access may take up to 1 hour after acceptance due to scheduled syncing.

Remove a guest administrator

  1. Go to Settings → Organization → Role administration.

  2. Select the Guest tab.

  3. Locate the guest administrator in the table.

  4. Select the ellipsis (⋯), then select Remove access.

  5. Confirm removal when prompted.

Result: The guest administrator is removed and no longer has access to your organization.


Instructions for the Classic Experience ⬇️

You can invite a guest administrator to manage your Drata account if you work with a Managed Security Service Provider (MSSP), a virtual CISO, or operate as a self-managed business unit with a centralized security and compliance team that requires access.

Prerequisites

  • Only users with a Drata Admin role can invite guest administrators.

  • Guest administrators have full access to the Drata application, equivalent to Admin roles.

  • For security reasons, guest administrators can be invited only from approved email domains.

  • Personal email addresses cannot be used to invite guest administrators.

  • After an invitation is sent, guest administrators may not have access for up to one hour. Invitations are processed during a scheduled data sync.

Invite a guest administrator

  1. On the Role Administration page, scroll down and select the Guest administrators card.

  2. Enter an email address of the guest administrator you would like to invite, and select the "Invite" button.

    Invite guest administrator

  3. Double confirm.

    Confirm guest administrator invitation

After you send the invitation, the guest administrator receives an email. They must accept the invitation to complete setup. Until then, their status in Drata appears as Pending name set up.

Guest administrators may not have access to your account immediately. A scheduled data sync processes invitations, and access may take up to one hour.

Remove a guest administrator

  1. On the Role Administration page, scroll down and select the Guest administrators card.

  2. Search for the guest administrator in the table and select the 'X' next to their name.

    Remove guest administrator

  3. Double confirm.

    Confirm guest administrator removal

Did this answer your question?