Skip to main content

Admin sign-in

Administrators sign in to the console one of three ways. The first admin who creates the workspace bootstraps it; everyone else is invited (see Roles & team). You do not have to set up SSO to get started — it’s a connect-later upgrade. Email/password works on day one, and you can require SSO later.

Sessions

Sessions are short-lived and refresh automatically in the background, so you stay signed in without long-lived credentials sitting in the browser. Signing out ends the session immediately. There’s nothing to configure.

Account recovery

  • Forgot password — use the reset link on the sign-in page. It emails a one-time link to your address.
  • Locked out — after repeated failed attempts an account is temporarily locked; wait and retry, or have another admin help.
  • Lost access entirely — another Owner or Admin on the workspace can re-invite you. A workspace always keeps at least one Admin/Owner (Cobalt blocks removing the last one), so you can’t lock the whole team out.

After SSO is configured

Once Enterprise SSO is active you can choose whether email/password sign-in stays available alongside it, or is turned off so all admin access flows through your IdP. Social login and email/password are independent toggles from SSO.
End users do not sign in here. They’re identified by their channel — see End-user identity.