Members & roles
Who can access your Cohortum workspace and what they can do—the roles Owner, Admin, Creator, and Viewer, plus per-project access.
Everyone in your workspace has a role, and that role decides what they see and what they can change. This page walks through the four roles, how project access narrows what Creators and Viewers can reach, and how to invite, promote, or revoke teammates from Settings → Members.
Only Admins and the Owner can open Settings → Members and send invites. Creators and Viewers never see the Members tab.
The four roles
Cohortum has four roles. There's no "Member" role.
| Role | What they can do |
|---|---|
| Owner | Full access to everything, and the only role that can grant or remove Admin. |
| Admin | Full access to every project and to all of Settings (Workspace, Members, Projects). Admins can always upload sources. |
| Creator | Can build and save analyses and cohorts in the projects they can access. Can upload sources only if Upload sources is enabled for them (see below). |
| Viewer | Read-only. Can open analyses, cohorts, and dashboards in their assigned projects, but can't build, save, or upload. |
Who can do what
| Capability | Owner | Admin | Creator | Viewer |
|---|---|---|---|---|
| View analyses, cohorts & insights | ✓ | ✓ | ✓ | ✓ |
| Build & save analyses | ✓ | ✓ | ✓ | — |
| Create & manage cohorts | ✓ | ✓ | ✓ | — |
| Share links & export PNG | ✓ | ✓ | ✓ | — |
| Upload & manage sources | ✓ | ✓ | ⚙ | — |
| Access every project | ✓ | ✓ | — | — |
| Workspace settings (name, retention) | ✓ | ✓ | — | — |
| Create & manage projects | ✓ | ✓ | — | — |
| Invite & manage members | ✓ | ✓ | — | — |
| Grant or remove the Admin role | ✓ | — | — | — |
✓ allowed · — not allowed · ⚙ only when the Upload sources toggle is on. Creators and Viewers reach only the projects you give them — see Project access.
Every workspace has exactly one Owner, set when Cohortum first provisions the workspace. The Owner never shows up in a role picker and can't be reassigned from the app. If you ever need to move the Owner role — say the sole Owner leaves the company or loses their account — contact Cohortum support. Give Admin to a trusted backup person now, just in case: Admin has near-equivalent access, so the workspace stays manageable if the Owner is ever out of reach.
The "Upload sources" toggle
Uploading event data is sensitive, so it's controlled separately from the role. The Upload sources switch (can_upload_sources) only matters for Creators:
- Admins and the Owner can always upload sources — the toggle is fixed on.
- Viewers can never upload — the toggle is fixed off.
- Creators can go either way. Turn it on for a data analyst who manages event logs. Leave it off for a Creator who only builds analyses on data someone else loaded.
When Upload sources is off for a Creator, the Sources nav item disappears for them. Instead of the upload wizard, they see the "ask a workspace admin to add one" empty state.
Project access
Admins and the Owner reach every project automatically. Creators and Viewers only see the projects you grant them — that's how you keep one team's clickstream data separate from another's.
The Project access column shows either All projects or a set of named project pills. For how projects split up sources, analyses, and cohorts, read Workspaces & projects.
The Members & Access screen
Open Settings → Members to see everyone in the workspace. The header reads Members & Access, with status pills (All / Active / Invited / Revoked) and a search box across the top.
Here's what each column tells you:
- User — the teammate's display name (click to rename inline).
- Email — their sign-in address (read-only).
- Joined — when they joined the workspace.
- Role — a badge showing Owner / Admin / Creator / Viewer.
- Upload sources — the per-Creator switch described above.
- Project access — All projects, or the specific project pills they can reach.
- Status — Active, Invited, or Revoked.
Select one or more rows — the Owner and your own row are locked — to bring up the bulk action bar: Edit role, Edit access, and Revoke. Edit role or Edit access applies your choice to every selected teammate at once.
Inviting a teammate
People can't sign themselves up. You invite them from here, and Cohortum provisions their account. If the email is new to Cohortum, a one-time temporary password shows once — copy it and hand it to the teammate securely. If the email already has a Cohortum account (say, in another workspace), no new password is generated: the person joins this workspace and signs in with their existing credentials, so they keep one identity across workspaces.
A row stays Invited until the teammate first signs in. When an invite goes stale — the temporary password got lost, the email was typed wrong, or the person never signed in — select that Invited row, click Revoke, then send a fresh invite to the right address. Re-inviting a new email issues a new one-time temporary password. (An email that already has a Cohortum account signs in with its existing credentials, so there's no password to reset here — point them to the standard sign-in and password-reset flow.)
Changing a role or revoking access
To change someone's role, select their row and use Edit role in the bulk action bar. Only the Owner can promote a teammate to Admin — Admins can hand out Creator and Viewer only.
To adjust which projects a Creator or Viewer can reach, select their row and use Edit access. To flip a single Creator's upload permission, use the Upload sources switch right on their row.
When someone leaves, select their rows and click Revoke. Confirm in the dialog, and they lose access to the workspace right away — their status flips to Revoked. Anything they built — analyses, cohorts, and sources — stays in the project, untouched. To bring them back later, select the revoked rows and choose Grant access, which restores their previous role, project access, and Upload sources setting.