Admin sign-in
Administrators sign in to the console one of three ways. The first admin who creates the workspace bootstraps it; everyone else is invited (see Roles & team).
You do not have to set up SSO to get started — it’s a connect-later upgrade.
Email/password works on day one, and you can require SSO later.
Sessions
Sessions are short-lived and refresh automatically in the background, so you stay signed in without long-lived credentials sitting in the browser. Signing out ends the session immediately. There’s nothing to configure.Account recovery
- Forgot password — use the reset link on the sign-in page. It emails a one-time link to your address.
- Locked out — after repeated failed attempts an account is temporarily locked; wait and retry, or have another admin help.
- Lost access entirely — another Owner or Admin on the workspace can re-invite you. A workspace always keeps at least one Admin/Owner (Cobalt blocks removing the last one), so you can’t lock the whole team out.
After SSO is configured
Once Enterprise SSO is active you can choose whether email/password sign-in stays available alongside it, or is turned off so all admin access flows through your IdP. Social login and email/password are independent toggles from SSO.End users do not sign in here. They’re identified by their channel — see
End-user identity.
