Skip to main content

Roles & team

Every administrator holds one or more roles. Roles are enforced on the server, on every request — the UI also hides what you can’t do, but the server is the authority.

Roles

A person can hold several roles at once (for example Admin + Billing); their effective access is the union. Roles are additive — there’s no “deny.”
The Billing role is only relevant on plans where you manage your own billing; on enterprise-contract workspaces it’s hidden.

Invite teammates

1

Open Settings → Team

You need the Admin or Owner role to invite or change members.
2

Enter emails and pick roles

Paste one or more email addresses and choose the role(s) to grant.
3

They accept the email invite

Each invitee gets a link, creates or signs in to their account, and lands in your workspace with the roles you assigned.
Pending invitations can be resent or revoked from the same screen.

Change or remove members

  • Edit roles — open a member and adjust their role set; changes take effect on their next request.
  • Remove — revokes their access to the workspace. You can’t remove yourself, and you can’t remove the last Admin/Owner — a workspace must always have one.

Letting your IdP assign roles

If you use Enterprise SSO, you can map your identity provider’s groups to Cobalt roles, so your directory decides who gets what instead of you assigning roles by hand.
  • Roles are set from someone’s groups each time they sign in through your provider. A group can carry several roles, and a person gets every role their groups carry.
  • Anyone whose groups match no mapping gets Member.
  • For people who sign in through SSO, the mapping wins: a role you change by hand here can be replaced at their next sign-in. Change the mapping, or the person’s groups in your provider, instead.
  • Owner is never granted by a mapping, and a mapping never removes the last Admin or Owner.
See Map groups to roles for the details.