Docs

Users and members

Admin → Users (/settings/users) lists the people in the current workspace. An owner or an admin can invite, change a role, and deactivate. A member cannot administer this screen. Calls go through workspace membership checks. A personal access token cannot administer users.

Roles

RoleWhat it is for
ownerThe installing membership. The last owner cannot be removed or demoted by the membership trigger
adminCan invite, change roles, and deactivate, same as an owner, on this screen
memberCan use Cockpit. Cannot administer members

Invite by email. If the person already has an Auth user, they are added. If they do not, Cockpit sends an Auth invite and then adds the membership. The invite link returns them to /login on your app origin. They still sign in with a one-time code. The login form does not sign up a stranger who was never invited.

Deactivate revokes that person's personal access tokens, removes their permission-set grants, and disables the membership. An access token that was already issued stays valid until it expires.

There is a separate user_profiles.is_admin flag used by a few database policies, including extraction-threshold writes. It is not the same switch as the workspace admin role. On a running workspace, treat the Users role as the control you have in the UI.

Domains

Admin → Domains is the label catalog (code, label, color, sort). Tasks and projects use it as a filter. It does not grant permissions.

Permission sets on a person

Admin → Perm Sets can attach sets to a user. That attachment is behind app_settings key feature.permission_sets_users, and the flag defaults off. While it is off, the user-grant table is not the enforcement path. Tokens carry their own scopes. Details are in Permissions and API keys.

Integrations

Admin → Integrations connects providers for the signed-in workspace: Google, GitHub, and X, plus Cursor Cloud. Disconnect revokes the stored connection. Connecting a provider is what allows sync and pull-request features to run. It does not by itself create users.

Notifications

Notifications (/notifications) is the in-app inbox for the signed-in user. Mark an item read or dismissed. Agents can do the same with cockpit_notifications_list and cockpit_notification_resolve when the token has cockpit:read or cockpit:write.