Control who can join a room
The room code is the default key. Add a password, require sign-in, or limit joiners to your email domains — set once on the Organization and applied per Workspace.
Every Room is reachable with its room code. Everything else — a password, a sign-in requirement, a domain allowlist — is an access policy you write once on the Organization and hand to as many Workspaces as you like.
Before you start#
You need to be an owner or admin of the Organization the Workspace belongs to. Resetting a room code works on any plan, and on a Personal Workspace its owner can do it; everything else on this page needs an Organization on a paid plan — see Which plan you need.
Planning and Retro share one set of access settings. Changes apply to both Rooms at once and cannot be set separately, so the Workspace needs a Retro Room before its Access section will do anything.
The room code is the default key#
Out of the box a Room has no password and no sign-in requirement. Anyone holding the link, or typing the code into Join a room, gets in and can vote. There is no participant account to create.
Planning and Retro each carry their own code. That is the entire access model until you attach a policy.
Reset a room code#
When a link has been shared somewhere it should not have been:
- Open Workspaces, choose the Workspace, then Planning Room or Retro Room.
- The current code sits in the page header. Click Reset room code and confirm.
- Share the new code with anyone who still needs to join.
Only that Room's code changes. Sessions, history, the queue and every other setting carry over, and people already in the Room stay connected. Resetting Planning does not reset Retro.
Write an access policy#
Policies belong to the Organization, not to a Room, so one policy can cover many Workspaces.
- Open Dashboard → Access controls.
- Click New policy and name it after the audience — "Internal teams".
- Turn on Room password, Sign-in required, or both.
- With sign-in on, list Allowed email domains, one per line or
comma-separated, with or without a leading
@. - Click Create policy.
The methods are alternatives rather than a checklist: whichever you enable is enough on its own. With both on, a correct password or an approved sign-in gets someone in.
Sign-in uses SprintBee's emailed one-time code. Two groups pass it: active members of the Room's Organization, always, and anyone whose email domain matches the allowlist. There is no list of individual addresses — admit a named person by adding them to the Organization. An empty domain list is valid and means only Organization members can join.
If your team joins from Microsoft Teams, add your directory's IDs under Allowed Microsoft Entra tenant IDs. Microsoft users are authorized on the tenant ID, never on an email claim.
Apply a policy#
There are two places to attach one, and the more specific always wins.
For a single Workspace, open it, choose Access, pick the policy under Access policy, and click Save access for both Rooms.
For everything else, set Organization default policy in Dashboard → Access controls. It covers every Room still set to Use organization default.
| What applies | When |
|---|---|
| The Room's own policy | The Workspace's Access section names a policy |
| The Organization default | The Workspace is on "Use organization default" |
| Room code only | Neither is set |
This is resolved fresh on every join attempt, so changing the Organization default takes effect immediately across every Room still inheriting it.
Set the shared room password#
One password covers both Rooms in a Workspace. In the Workspace's Access section, type it under Shared room password and save. Leaving the field blank keeps whatever password is already set; tick Remove passwords from both Rooms to clear it.
Passwords are salted and hashed with scrypt before storage. SprintBee never holds one in plain text and cannot tell you an existing password — set a new one instead.
What joiners see#
When a password is in force, the join form shows a Room password field beside the room code. If the policy also accepts sign-in, a line underneath offers "Or sign in with an approved email to join".
When sign-in is the only way in, the form says the room requires sign-in with an approved email and the button reads Sign in to join. Someone already signed in with a qualifying account joins straight through.
Which plan you need#
| Capability | Plan |
|---|---|
| Room code, and resetting it | Every plan, Free included |
| Room password | Paid |
| Required sign-in | Paid |
| Email-domain and Entra tenant restriction | Paid |
| Organization default policy | Paid |
Gating follows the Organization that owns the Workspace. Pro, Pro Plus and Pro Ultra all include the same access controls; Free includes none of them.
On Free, Access controls and a Workspace's Access section stay visible but read-only. Policies left from an earlier paid period still list, marked "Reactivate a paid plan to change", so nothing you configured is lost if a plan lapses — it simply stops being editable.
A Room that is not part of an Organization cannot take a policy at all.
Last updated