Team & Access
The Team & Access page lets admins control who has access and what they can do.
Accessing Team & Access
Section titled “Accessing Team & Access”- Click Settings in the sidebar
- Select Team & Access
- View your team members list
Viewing users
Section titled “Viewing users”The user list shows:
| Column | Description |
|---|---|
| Name | Display name |
| Login email address | |
| Role | Permission level |
| Dashboard Groups | Groups the user belongs to |
| 2FA Status | Whether 2FA is enabled |
| Last Active | Most recent activity |
Adding users
Section titled “Adding users”Step 1: Click Add User
Section titled “Step 1: Click Add User”- On Team & Access, click Add User
- The new user form opens
Step 2: Enter user details
Section titled “Step 2: Enter user details”| Field | Description |
|---|---|
| User’s email (required) | |
| Name | Display name |
| Role | Permission level (Admin, Staff, Member) |
| Dashboard Groups | Groups to assign |
Step 3: Send invitation
Section titled “Step 3: Send invitation”- Review the info
- Click Send Invitation
- User gets an email to set up their account
Invitation process
Section titled “Invitation process”- User receives invitation email
- Clicks link to create password
- Sets up account
- Gets access based on assigned role and groups
Editing users
Section titled “Editing users”Changing user details
Section titled “Changing user details”- Find the user
- Click Edit (pencil icon)
- Modify name, role, timezone, dashboard groups, or email digest settings
- Click Save
Changing user role
Section titled “Changing user role”- Edit the user
- Select new role from dropdown
- Save changes
- New permissions apply immediately
Available user roles are Admin, Staff, and Member. External viewers should use Share Links instead of a separate guest role.
Managing Dashboard Group membership
Section titled “Managing Dashboard Group membership”- Edit the user
- Add or remove group assignments
- Save changes
- User sees updated dashboards
Managing email digests (Business+)
Section titled “Managing email digests (Business+)”Admins on Business or Starship can manage a user’s email digest from the edit screen.
- Open the user in Settings → Team & Access
- In Email Digest, turn on Enable email digest
- Choose Daily or Weekly
- Choose a send time from Send at
- Click Save
The digest is sent using the user’s timezone. If the setting has never been changed, the default is disabled, with Daily and 8:00 AM selected when you turn it on.
What the digest includes:
- Audit log activity only
- Create, update, and delete changes
- A summary of what changed and who made the change
If there are no qualifying changes during the period, no digest email is sent.
Configuring user permissions (Professional+)
Section titled “Configuring user permissions (Professional+)”Admins on Professional, Business, or Starship tiers can configure granular permissions:
- Edit the user
- Open the Access & Permissions tab
- Adjust dataset and feature permission controls
- Save changes
On Access & Permissions, company admins can also set an optional User Weekly Cap for existing users; save the user dialog to apply it. See User Weekly Caps.
Dataset permissions
Section titled “Dataset permissions”Dataset permissions are configured at the top of the user edit page.
| Control | What it does |
|---|---|
| Access Mode | Chooses whether the user gets Full Access, a Blacklist, or a Whitelist. |
| Default Permission Level | Sets the default dataset permission for allowed datasets: Read + Write or Read Only. |
| Allowed / Blocked Datasets | The dataset picker used when Access Mode is Blacklist or Whitelist. |
| Per-Dataset Permission Overrides | In Whitelist mode for non-members, lets you override individual datasets to Default, Read, or Read + Write. |
Role-specific behavior:
- Admin users always keep full dataset access with read/write permissions. The page shows a summary, but admins do not use custom dataset restrictions.
- Staff users can use all dataset permission controls.
- Member users use dataset permissions only for AI Chat access. They still cannot open the raw Datasets or Modified Datasets pages directly, and their dataset access stays Read Only.
Access modes:
- Full Access: the user can reach every dataset allowed by their role.
- Blacklist: the user can reach every dataset except the selected ones.
- Whitelist: the user can reach only the selected datasets.
Default permission levels:
- Read Only: the user can use the dataset in widgets and downstream features but cannot edit the source dataset.
- Read + Write: the user can use and edit the dataset.
Feature permissions
Section titled “Feature permissions”Feature permissions are the toggle list in the lower half of the Access & Permissions tab. These toggles control feature access or write actions, depending on the feature. Use Reset to Role Defaults to restore the standard defaults for the selected role.
| Toggle | What turning it on does |
|---|---|
| Dashboards & Widgets | Enables dashboard and widget editing actions. Dashboard visibility still follows Dashboard Groups. |
| Integrations | Enables adding, editing, and reconnecting standard integrations. |
| Modified Datasets | Enables creating and editing Modified Datasets. |
| Dynamic Filter Variables | Enables creating, editing, and deleting dynamic filter variables. |
| Share Links | Enables creating, editing, duplicating, moving, and deleting dashboard share links. |
| Resplendent API | Enables managing Resplendent API credentials. Requires the Starship tier. |
| Custom Integrations | Enables creating and editing custom integrations. |
| Templates | Enables managing dashboard and widget templates in the Template Gallery. |
| Reports | Enables report blueprint management actions and report-related editing actions. |
| Widget Snapshots | Enables widget snapshot creation and deletion actions where snapshot tools are available. |
| Soundboard | Enables uploading and managing threshold alert sounds. |
| Tags | Enables creating, editing, and deleting tags. |
| AI Chat Access | Enables access to Eric / AI Chat. For members, this still follows the dataset rules above and remains read-only. |
Important behavior:
- Non-AI feature toggles follow the selected role defaults.
- AI Chat Access defaults on for Admins and Giga Admins, but not for Staff or Members.
- Members only get the AI Chat Access toggle.
- AI Chat Access appears for all companies.
- Company Knowledge updates are controlled by Company Knowledge Update Permission.
- Some toggles make a page read-only instead of hiding it completely. Tier limits and role requirements can still block separate actions.
Removing users
Section titled “Removing users”Deactivating a user
Section titled “Deactivating a user”- Find the user
- Click Deactivate
- User can no longer log in
- Account can be reactivated later
Deleting a user
Section titled “Deleting a user”- Find the user
- Click Delete
- Confirm
If the deletion succeeds, a User deleted successfully message appears and you are returned to the user list. The account is permanently removed.
If the user still owns records that block deletion — such as OAuth-backed data sources or soundboard items — a message appears explaining what is in the way and what to do next. Remove or reassign those records, then try again.
Other dependent records can also block deletion. The error message tells you when this happens.
User status
Section titled “User status”| Status | Description |
|---|---|
| Active | Can log in and use the system |
| Invited | Invitation sent, awaiting setup |
| Deactivated | Account disabled, cannot log in |
Resending invitations
Section titled “Resending invitations”If a user didn’t get their invitation:
- Find the user (status: Invited)
- Click Resend Invitation
- New email is sent
- Previous link is invalidated
Password reset
Section titled “Password reset”User-initiated reset
Section titled “User-initiated reset”- Go to sign-in page
- Click Forgot Password
- Enter email address
- Follow email instructions
Admin-initiated reset
Section titled “Admin-initiated reset”- Find the user
- Click Reset Password
- User receives reset email
Two-Factor Authentication
Section titled “Two-Factor Authentication”Viewing 2FA status
Section titled “Viewing 2FA status”The user list shows:
- Enabled: 2FA is active
- Disabled: 2FA not set up
Requiring 2FA
Section titled “Requiring 2FA”Admins can:
- Encourage users to enable 2FA
- Enterprise plans can enforce 2FA
Disabling 2FA for a user
Section titled “Disabling 2FA for a user”Admins can turn off 2FA for another user from the edit dialog:
- Find the user and click Edit
- In the Security section, switch off the Two-factor authentication toggle
- Click Update
This clears the user’s 2FA secret and recovery codes. The user can re-enable 2FA later from their own profile.
Admins cannot disable their own 2FA from the user edit page, and admins cannot enable 2FA for another user.
If a user loses their authenticator and has no recovery codes, use Disabling 2FA for a user above. After an admin turns 2FA off, the user can set it up again from their own profile.
Bulk operations
Section titled “Bulk operations”Exporting user list
Section titled “Exporting user list”- Open Settings → Team & Access
- If needed, use the search box to narrow the list
- Click Export CSV
- Download the
users.csvfile
The export includes the users currently shown by the table. If you filter the list with search first, the CSV contains only those matching rows.
Bulk invitations
Section titled “Bulk invitations”For many users:
- Prepare a CSV with emails and names
- Use bulk import (contact support)
- Invitations sent to all
Self-service features
Section titled “Self-service features”User profile
Section titled “User profile”Users can manage their own:
- Display name
- Password
- 2FA settings
- Email digest preferences
What users cannot change
Section titled “What users cannot change”- Their own role
- Dashboard group assignments
- Account deletion
Troubleshooting
Section titled “Troubleshooting”User can’t log in
Section titled “User can’t log in”- Verify email is correct
- Check account isn’t deactivated
- Try password reset
- Verify 2FA code is correct
User can’t see dashboards
Section titled “User can’t see dashboards”- Check dashboard group assignments
- Verify dashboards are in assigned groups
- Confirm role has view permission
Invitation not received
Section titled “Invitation not received”- Check spam/junk folder
- Verify email is correct
- Resend the invitation
- Check email deliverability
2FA issues
Section titled “2FA issues”- Verify device time is synced
- Try using a recovery code
- Ask an admin to disable 2FA from the user edit screen, then re-enable it from your profile
Company access requests
Section titled “Company access requests”When a new user’s verified email domain matches your company’s domain, they can request access instead of creating a separate company. Admins review these requests on the Team & Access page.
Reviewing requests
Section titled “Reviewing requests”- Open Settings → Team & Access
- Look for the Review Company access requests panel above the user list
- Each request shows the requester’s name, email, matching domain, and when it was sent
| Action | What it does |
|---|---|
| Approve | Grants the user access to your company |
| Deny | Rejects the request. The user can still create a separate company |
Decisions are immediate. Approved users can log in normally. Denied users receive an email notification and can choose to create their own company instead.