Short answer: keep an invitation in a pending state, verify the claimant's identity, and create the user record only after that proof succeeds. For a B2B SaaS product, make the same state machine own deletion: a GDPR delete must revoke every session before the account disappears.

Here is the decision note I use when reviewing an invite flow. It is deliberately boring. Boring auth survives audits.

Strength

Cost

Best fit