Skip to main content

Identity & access

Cobalt has two distinct kinds of identity. Keep them separate in your head — they are configured in different places and serve different purposes. Everything an administrator does is tenant-scoped. End users never sign in to the console — they are identified by the channel they arrive through, and Cobalt maps that inbound identity to a known person.

Administrator topics

Admin sign-in

Email/password, social login, sessions, and account recovery.

Roles & team

What each role can do, and how to invite and manage your team.

Enterprise SSO

Connect SAML so your team signs in with corporate credentials — and map IdP groups to Cobalt roles.

SCIM provisioning

Auto-provision and de-provision users from your identity provider.

End-user topics

End-user identity

Canonical users, channel identities, resolution rules, the review queue, and trust tiers.

Web widget authentication

Identify users on an embedded widget without a second sign-in.
For where identity fits in the bigger picture, see How Cobalt works.