Skip to main content

Admin sign-in

Administrators sign in to the console one of three ways. The first admin who creates the workspace bootstraps it; everyone else is invited (see Roles & team). You do not have to set up SSO to get started — it’s a connect-later upgrade. Email/password works on day one, and you can add SSO later.

Sessions

Sessions are short-lived and refresh automatically in the background, so you stay signed in without long-lived credentials sitting in the browser. Signing out ends the session immediately. There’s nothing to configure.

Account recovery

  • Forgot password — use the reset link on the sign-in page. It emails a one-time link to your address.
  • Locked out — after repeated failed attempts an account is temporarily locked; wait and retry, or have another admin help.
  • Lost access entirely — another Owner or Admin on the workspace can re-invite you. A workspace always keeps at least one Admin/Owner (Cobalt blocks removing the last one), so you can’t lock the whole team out.

After SSO is configured

Once Enterprise SSO is active, everyone whose email address is on your SSO domain signs in through your identity provider. They’re sent to your provider instead of the password box, even if they had a password before. Anyone on your team with an email address on a different domain (a contractor, or a personal address) can still sign in with email and password. If you don’t want that, remove them on Settings › Team (see Roles & team), or invite them again with an address on your SSO domain. There’s no setting in Cobalt that turns password sign-in off for everyone.
With SSO active, your identity provider is the only way in for everyone on your SSO domain. If your provider is unreachable, those people can’t sign in until it’s back. Test SSO with a real sign-in first (the setup does this for you).
The people your agents talk to never sign in here. Chat sign-in is separate from admin sign-in and is set up per agent — see How end-user identity works.