Let colleagues join by email domain
Decide whether someone signing up with your company email lands in your workspace straight away or waits for an admin to approve them.

When someone signs up with an email on your company domain, Document eSign already knows they belong with you. One switch decides what happens next: they join immediately, or they send a request an admin approves. It sits under Settings > Policies & audit as Auto-enroll from matching email domain.
Who can do this
Workspace admins. The switch is available on every plan.
Pick how colleagues get in
-
Open Settings, then Policies & audit.
-
Find Auto-enroll from matching email domain in the Work policies card.
-
Leave it on when you trust anyone with a company address, for example a small team where everyone should be able to send. New signups on your domain become members the moment they finish signing up.
-
Switch it off when you want a gate. Those signups instead submit a join request, and nobody reaches your documents until an admin says yes.

The change saves on the spot.
Which email domains count
Your workspace matches on the domain of the address it was created with. Set up from someone at acme.com and every later signup ending in acme.com meets the gate. There's no field to edit that domain.
Personal mailboxes never count. gmail.com, outlook.com, yahoo.com, icloud.com and the rest of the consumer providers are excluded on purpose, so a colleague using one of those gets a workspace of their own instead of yours. Bring them in with an ordinary invitation from the Team page.
Approve or decline a join request
-
Open Settings, then Team.
-
A Join requests card appears above the member list whenever someone is waiting, with a count such as "2 pending" next to the heading. No card means no requests.
-
Check the person and the address they used. The Requested column shows the day it came in.
-
Click Approve to add them, or Decline to turn them away.

Approving creates their account and adds them as a Member, and they appear in the member list right away. Both outcomes send the person an email, so you don't have to write to them yourself.
What the person sees
Their signup pauses on a Join your team. screen that names your workspace under the line "Your email matches an existing workspace". With auto-enroll on, the button reads Join followed by your workspace name, and they're in one click later. With it off, the button reads Request to join followed by your workspace name, and the screen usually names the admin who will review it.
A pending request has no expiry date. It sits on the Join requests card until an admin decides it, and Approve and Decline are both final for that request. Someone turned away can start again from a fresh signup if you change your mind.
If something goes wrong
- A colleague signed up and got their own empty workspace. Their address is on a different domain from the one your workspace owns, so the gate never fired. Invite them from the Team page instead.
- Approve fails and mentions your member limit. Every seat on your plan is taken. Free one up or move to a bigger plan, then approve again.
- A coral Upgrade chip sits next to the Work policies card title. That chip covers the other policies in the card, which need a paid plan. Auto-enroll isn't one of them and its switch still works on Free.
- No Join requests card is showing. Either nobody is waiting, or auto-enroll is on and everyone is joining without asking.
- Approve returns an error about the email. That address already has a Document eSign account, so it cannot be created a second time. Ask them to sign in and use an invitation instead.
- You can't see the Team or Policies tabs at all. Both are admin-only.
Frequently asked questions
Which domain does my workspace match on?
The one from the email address the workspace was created with. If it was set up by someone at acme.com, every later signup ending in acme.com meets the gate. There is no field to edit the domain, and a workspace created from a personal mailbox matches nobody.
Do people on Gmail or Outlook ever match?
No. Consumer mailbox providers are excluded on purpose, so gmail.com, outlook.com, yahoo.com, icloud.com and their relatives never count as a work domain. Someone signing up from one of those addresses gets a fresh workspace of their own rather than landing in yours, and the way to bring them in is an ordinary invitation from the Team page.
What role does an approved person get?
Member, which is the most limited role. They can send their own documents and see only what they created. Change it afterwards from the Team page if they need more, for example Manager to see what their teammates are sending or Admin for full workspace control.
What happens when all our seats are taken?
Auto-enroll quietly stops applying and the person is offered the join request route instead. Approving still needs a free seat, so remove someone who has left or move up a plan first. That way a rush of domain signups can never push you past your plan.
Does the person hear back either way?
Yes. Approve and they get an email telling them they are in, then they sign in normally. Decline and they get an email too, without a reason attached. Nothing is left hanging, and a request can only be decided once.
Keep going
Join an existing workspace: invite, domain match, or request
Accept an admin's invite, join automatically with a matching company email, request access and wait for approval, or restore a workspace scheduled for deletion.
ReadInvite teammates and manage seatsGrowth and up
Send an invite from Settings > Team, watch it move from Invited to Active, revoke the ones you no longer want, and see how seats are counted.
ReadDocument policies: signing window, reminders and forwardingGrowth and up
Set the signing window, reminder cadence and forwarding rule once, and every document you send afterwards starts from those values.
ReadWorkspace roles - Admin, Manager, Member and billing
What each of the three workspace roles can do, who is allowed to change a role, and why the last admin cannot be demoted or removed.
Read