Admin sign-in
Administrators sign in to the console one of three ways. The first admin who creates the workspace bootstraps it; everyone else is invited (see Roles & team).
You do not have to set up SSO to get started — it’s a connect-later upgrade.
Email/password works on day one, and you can add SSO later.
Sessions
Sessions are short-lived and refresh automatically in the background, so you stay signed in without long-lived credentials sitting in the browser. Signing out ends the session immediately. There’s nothing to configure.Account recovery
- Forgot password — use the reset link on the sign-in page. It emails a one-time link to your address.
- Locked out — after repeated failed attempts an account is temporarily locked; wait and retry, or have another admin help.
- Lost access entirely — another Owner or Admin on the workspace can re-invite you. A workspace always keeps at least one Admin/Owner (Cobalt blocks removing the last one), so you can’t lock the whole team out.
After SSO is configured
Once Enterprise SSO is active, everyone whose email address is on your SSO domain signs in through your identity provider. They’re sent to your provider instead of the password box, even if they had a password before. Anyone on your team with an email address on a different domain (a contractor, or a personal address) can still sign in with email and password. If you don’t want that, remove them on Settings › Team (see Roles & team), or invite them again with an address on your SSO domain. There’s no setting in Cobalt that turns password sign-in off for everyone.The people your agents talk to never sign in here. Chat sign-in is separate
from admin sign-in and is set up per agent — see
How end-user identity works.
