Skip to main content

Roles & team

Every administrator holds one or more roles. Roles are enforced on the server, on every request — the UI also hides what you can’t do, but the server is the authority.

Roles

A person can hold several roles at once (for example Admin + Billing); their effective access is the union. Roles are additive — there’s no “deny.”
The Billing role is only relevant on plans where you manage your own billing; on enterprise-contract workspaces it’s hidden.

Invite teammates

1

Open Settings → Team

You need the Admin or Owner role to invite or change members.
2

Enter emails and pick roles

Paste one or more email addresses and choose the role(s) to grant.
3

They accept the email invite

Each invitee gets a link, creates or signs in to their account, and lands in your workspace with the roles you assigned.
Pending invitations can be resent or revoked from the same screen.

Change or remove members

  • Edit roles — open a member and adjust their role set; changes take effect on their next request.
  • Remove — revokes their access to the workspace. You can’t remove yourself, and you can’t remove the last Admin/Owner — a workspace must always have one.

Letting your IdP assign roles

If you use Enterprise SSO, you can map your identity provider’s groups to Cobalt roles, so role assignment is governed by your directory instead of by hand. See Map groups to roles.