Skip to content

Team & Access

The Team & Access page lets admins control who has access and what they can do.

  1. Click Settings in the sidebar
  2. Select Team & Access
  3. View your team members list

The user list shows:

Column Description
Name Display name
Email Login email address
Role Permission level
Dashboard Groups Groups the user belongs to
2FA Status Whether 2FA is enabled
Last Active Most recent activity
  1. On Team & Access, click Add User
  2. The new user form opens
Field Description
Email User’s email (required)
Name Display name
Role Permission level (Admin, Staff, Member)
Dashboard Groups Groups to assign
  1. Review the info
  2. Click Send Invitation
  3. User gets an email to set up their account
  1. User receives invitation email
  2. Clicks link to create password
  3. Sets up account
  4. Gets access based on assigned role and groups
  1. Find the user
  2. Click Edit (pencil icon)
  3. Modify name, role, timezone, dashboard groups, or email digest settings
  4. Click Save
  1. Edit the user
  2. Select new role from dropdown
  3. Save changes
  4. New permissions apply immediately

Available user roles are Admin, Staff, and Member. External viewers should use Share Links instead of a separate guest role.

  1. Edit the user
  2. Add or remove group assignments
  3. Save changes
  4. User sees updated dashboards

Admins on Business or Starship can manage a user’s email digest from the edit screen.

  1. Open the user in SettingsTeam & Access
  2. In Email Digest, turn on Enable email digest
  3. Choose Daily or Weekly
  4. Choose a send time from Send at
  5. Click Save

The digest is sent using the user’s timezone. If the setting has never been changed, the default is disabled, with Daily and 8:00 AM selected when you turn it on.

What the digest includes:

  • Audit log activity only
  • Create, update, and delete changes
  • A summary of what changed and who made the change

If there are no qualifying changes during the period, no digest email is sent.

Configuring user permissions (Professional+)

Section titled “Configuring user permissions (Professional+)”

Admins on Professional, Business, or Starship tiers can configure granular permissions:

  1. Edit the user
  2. Open the Access & Permissions tab
  3. Adjust dataset and feature permission controls
  4. Save changes

On Access & Permissions, company admins can also set an optional User Weekly Cap for existing users; save the user dialog to apply it. See User Weekly Caps.

Dataset permissions are configured at the top of the user edit page.

Control What it does
Access Mode Chooses whether the user gets Full Access, a Blacklist, or a Whitelist.
Default Permission Level Sets the default dataset permission for allowed datasets: Read + Write or Read Only.
Allowed / Blocked Datasets The dataset picker used when Access Mode is Blacklist or Whitelist.
Per-Dataset Permission Overrides In Whitelist mode for non-members, lets you override individual datasets to Default, Read, or Read + Write.

Role-specific behavior:

  • Admin users always keep full dataset access with read/write permissions. The page shows a summary, but admins do not use custom dataset restrictions.
  • Staff users can use all dataset permission controls.
  • Member users use dataset permissions only for AI Chat access. They still cannot open the raw Datasets or Modified Datasets pages directly, and their dataset access stays Read Only.

Access modes:

  • Full Access: the user can reach every dataset allowed by their role.
  • Blacklist: the user can reach every dataset except the selected ones.
  • Whitelist: the user can reach only the selected datasets.

Default permission levels:

  • Read Only: the user can use the dataset in widgets and downstream features but cannot edit the source dataset.
  • Read + Write: the user can use and edit the dataset.

Feature permissions are the toggle list in the lower half of the Access & Permissions tab. These toggles control feature access or write actions, depending on the feature. Use Reset to Role Defaults to restore the standard defaults for the selected role.

Toggle What turning it on does
Dashboards & Widgets Enables dashboard and widget editing actions. Dashboard visibility still follows Dashboard Groups.
Integrations Enables adding, editing, and reconnecting standard integrations.
Modified Datasets Enables creating and editing Modified Datasets.
Dynamic Filter Variables Enables creating, editing, and deleting dynamic filter variables.
Share Links Enables creating, editing, duplicating, moving, and deleting dashboard share links.
Resplendent API Enables managing Resplendent API credentials. Requires the Starship tier.
Custom Integrations Enables creating and editing custom integrations.
Templates Enables managing dashboard and widget templates in the Template Gallery.
Reports Enables report blueprint management actions and report-related editing actions.
Widget Snapshots Enables widget snapshot creation and deletion actions where snapshot tools are available.
Soundboard Enables uploading and managing threshold alert sounds.
Tags Enables creating, editing, and deleting tags.
AI Chat Access Enables access to Eric / AI Chat. For members, this still follows the dataset rules above and remains read-only.

Important behavior:

  • Non-AI feature toggles follow the selected role defaults.
  • AI Chat Access defaults on for Admins and Giga Admins, but not for Staff or Members.
  • Members only get the AI Chat Access toggle.
  • AI Chat Access appears for all companies.
  • Company Knowledge updates are controlled by Company Knowledge Update Permission.
  • Some toggles make a page read-only instead of hiding it completely. Tier limits and role requirements can still block separate actions.
  1. Find the user
  2. Click Deactivate
  3. User can no longer log in
  4. Account can be reactivated later
  1. Find the user
  2. Click Delete
  3. Confirm

If the deletion succeeds, a User deleted successfully message appears and you are returned to the user list. The account is permanently removed.

If the user still owns records that block deletion — such as OAuth-backed data sources or soundboard items — a message appears explaining what is in the way and what to do next. Remove or reassign those records, then try again.

Other dependent records can also block deletion. The error message tells you when this happens.

Status Description
Active Can log in and use the system
Invited Invitation sent, awaiting setup
Deactivated Account disabled, cannot log in

If a user didn’t get their invitation:

  1. Find the user (status: Invited)
  2. Click Resend Invitation
  3. New email is sent
  4. Previous link is invalidated
  1. Go to sign-in page
  2. Click Forgot Password
  3. Enter email address
  4. Follow email instructions
  1. Find the user
  2. Click Reset Password
  3. User receives reset email

The user list shows:

  • Enabled: 2FA is active
  • Disabled: 2FA not set up

Admins can:

  • Encourage users to enable 2FA
  • Enterprise plans can enforce 2FA

Admins can turn off 2FA for another user from the edit dialog:

  1. Find the user and click Edit
  2. In the Security section, switch off the Two-factor authentication toggle
  3. Click Update

This clears the user’s 2FA secret and recovery codes. The user can re-enable 2FA later from their own profile.

Admins cannot disable their own 2FA from the user edit page, and admins cannot enable 2FA for another user.

If a user loses their authenticator and has no recovery codes, use Disabling 2FA for a user above. After an admin turns 2FA off, the user can set it up again from their own profile.

  1. Open SettingsTeam & Access
  2. If needed, use the search box to narrow the list
  3. Click Export CSV
  4. Download the users.csv file

The export includes the users currently shown by the table. If you filter the list with search first, the CSV contains only those matching rows.

For many users:

  1. Prepare a CSV with emails and names
  2. Use bulk import (contact support)
  3. Invitations sent to all

Users can manage their own:

  • Display name
  • Password
  • 2FA settings
  • Email digest preferences
  • Their own role
  • Dashboard group assignments
  • Account deletion
  • Verify email is correct
  • Check account isn’t deactivated
  • Try password reset
  • Verify 2FA code is correct
  • Check dashboard group assignments
  • Verify dashboards are in assigned groups
  • Confirm role has view permission
  • Check spam/junk folder
  • Verify email is correct
  • Resend the invitation
  • Check email deliverability
  • Verify device time is synced
  • Try using a recovery code
  • Ask an admin to disable 2FA from the user edit screen, then re-enable it from your profile

When a new user’s verified email domain matches your company’s domain, they can request access instead of creating a separate company. Admins review these requests on the Team & Access page.

  1. Open SettingsTeam & Access
  2. Look for the Review Company access requests panel above the user list
  3. Each request shows the requester’s name, email, matching domain, and when it was sent
Action What it does
Approve Grants the user access to your company
Deny Rejects the request. The user can still create a separate company

Decisions are immediate. Approved users can log in normally. Denied users receive an email notification and can choose to create their own company instead.