CogLake User Guide
Administration

Users, roles, and permissions

Manage identities and combine product permissions with workspace and connector access.

Users

Open Administration → Workspace → Members to invite a member, edit identity details, assign one or more roles, require a password change, disable access, or remove an account. Search and filter by status or role when the member list grows.

Invite a member

  1. Select Invite member and enter the person's email address and optional display name.
  2. Choose the platform role and any additional custom roles for this workspace.
  3. Send the invitation. The single-use link expires automatically.
  4. Use the pending invitations list to resend or revoke an invitation before it is accepted.

An existing CogLake identity keeps its current sign-in credentials and gains a separate membership in this workspace. A new identity chooses its name and password while accepting the invitation. Roles are stored per workspace, so the same person can be an administrator in one workspace and a member in another.

OIDC or SCIM-provisioned users can be associated with external email and group mappings. A stable internal user ID is used for access decisions; email remains identity and mapping information rather than the sole authorization key.

Platform role

Every custom role has a platform role of either Administrator or Member:

  • Administrator is the trusted administrative baseline and receives the complete administrative permission set.
  • Member starts without administrative authority and receives only the granular permissions you select.

Use Member for department, project, support, and read-only roles. Create as few platform-administrator roles as possible.

Product permissions

Role editor with platform role, product permissions, and resource access sections.
Roles combine a platform baseline with explicit product permissions and resource-specific access.
PermissionAllows
Manage usersUser lifecycle and identity mappings
Manage rolesRole policies and permission-preview searches
Edit installation settingsAuthentication, appearance, backup, and repair operations
Read / export reportsAudit and operational reporting
Manage connectorsConnector setup, sync, diagnostics, and indexing operations
Read / write knowledgeRead or modify internal knowledge content
Create personal / company workspaceCreate the respective workspace type
Use search and retrievalDiscover, answer, and retrieval requests

Resource access

Product permissions are combined with resource scopes:

  • Knowledge bases support None, Read, Write, and Admin.
  • Connectors support None, Search, Read, and Write.
  • A wildcard scope can apply to all matching resources; an explicit resource entry takes precedence.

The source ACL is checked after these scopes. For example, knowledge:read plus connector Read still does not reveal a Google Drive file that the connected source does not grant to the user's principals.

Built-in roles cannot be removed. A custom role must have no assigned members before it can be deleted; reassign affected members first.

  1. Keep one small administrator role.
  2. Create business roles with platform role Member.
  3. Select only required product permissions.
  4. Add the exact workspaces and connectors each role needs.
  5. Use Discover's Preview search as role control to validate the result boundary.

On this page