Roles & team
Every administrator holds one or more roles. Roles are enforced on the server, on every request — the UI also hides what you can’t do, but the server is the authority.Roles
A person can hold several roles at once (for example Admin + Billing); their
effective access is the union. Roles are additive — there’s no “deny.”
The Billing role is only relevant on plans where you manage your own
billing; on enterprise-contract workspaces it’s hidden.
Invite teammates
1
Open Settings → Team
You need the Admin or Owner role to invite or change members.
2
Enter emails and pick roles
Paste one or more email addresses and choose the role(s) to grant.
3
They accept the email invite
Each invitee gets a link, creates or signs in to their account, and lands in
your workspace with the roles you assigned.
Change or remove members
- Edit roles — open a member and adjust their role set; changes take effect on their next request.
- Remove — revokes their access to the workspace. You can’t remove yourself, and you can’t remove the last Admin/Owner — a workspace must always have one.
Letting your IdP assign roles
If you use Enterprise SSO, you can map your identity provider’s groups to Cobalt roles, so your directory decides who gets what instead of you assigning roles by hand.- Roles are set from someone’s groups each time they sign in through your provider. A group can carry several roles, and a person gets every role their groups carry.
- Anyone whose groups match no mapping gets Member.
- For people who sign in through SSO, the mapping wins: a role you change by hand here can be replaced at their next sign-in. Change the mapping, or the person’s groups in your provider, instead.
- Owner is never granted by a mapping, and a mapping never removes the last Admin or Owner.
