Skip to main content

Identity & access

Cobalt has two distinct kinds of identity. Keep them separate in your head — they are configured in different places and serve different purposes. Everything an administrator does is tenant-scoped. End users never sign in to the console — they are identified by the channel they arrive through, and Cobalt maps that inbound identity to a known person.

Administrator topics

Administrators sign in to the console with email and password, a Google or Microsoft account, or your company’s identity provider through Enterprise SSO. What each person can do is set by their roles, which you assign on the Team page or let your identity provider’s groups decide. Admin sign-in is separate from how your agents recognize people in chat.

Admin sign-in

The ways to sign in, sessions, account recovery, and turning password sign-in off once SSO works.

Roles & team

What each role can do, and how to invite and manage your team.

Enterprise SSO

A guided setup so your team signs in through your identity provider — and its groups can set their Cobalt roles.

People sync (SCIM)

Send your people to Cobalt from your directory, and tell it when someone leaves.

End-user topics

End-user identity follows one model, set up in four places:
  1. Settings holds your lists. Your company’s identity providers (the systems your people sign in with, such as Microsoft Entra ID, Google Workspace or Okta) and your directories (the systems Cobalt reads groups from) live in Settings › Identity.
  2. Each agent picks one of each, on the agent’s Identity page: one Provider to check who people are, and one Directory to read their groups from.
  3. Each channel picks how people get in — anonymously, with a token your own site hands over, or by signing in with their work account.
  4. Each capability says which groups may reach it. A tool, skill, knowledge collection or live agent handoff can be limited to Allowed groups from the agent’s directory.

How end-user identity works

The model, the four ways people get in, and who counts as one of your people.

Identity providers

Register Microsoft Entra ID, Google Workspace, Okta or another provider, and let your people sign in with it.

Directories

Connect the directory Cobalt reads groups from.

Allowed groups

Limit a capability to the people in certain groups.

Troubleshooting sign-in

What each provider status and sign-in problem means, and what your people see.

Signing keys

Sign your own tokens for the Embedded token mode.
For where identity fits in the bigger picture, see How Cobalt works.