Team Management

Team Management

Invite teammates, assign roles, and understand workspace permissions in CookieShift.

Manage who can access your CookieShift workspace, what they can change, and how billing ownership works.

Overview

Team management covers workspace membership: inviting users by email, assigning roles (Owner, Admin, Editor, Analyst, Viewer), switching between workspaces, and restricting billing changes to owners.

Why it matters

Consent configuration and scan data are sensitive. Role-based access limits accidental banner changes, exposes the right reports to analysts, and keeps payment details with owners only.

Setup

  1. Sign in as Owner or Administrator.
  2. Open SettingsTeam Permissions (or Workspace settings).
  3. Enter teammate email and select role.
  4. Send invite — they accept via email link (Accept invite flow).
  5. Teammate selects the workspace in the header switcher if they belong to multiple.
  6. Revoke access promptly when someone leaves (remove member or disable account per your policy).

Examples

RoleTypical use
EditorDay-to-day Consent Setup and Scanner
AnalystReports and consent log exports only
ViewerRead dashboards for executives
AdministratorEverything except billing deletion
OwnerBilling, AI keys, workspace deletion

Troubleshooting

SymptomLikely causeFix
Invite not receivedSpam filter or wrong emailResend; verify SMTP in System Health
Cannot access BillingRole is not OwnerOwner upgrades or shares portal link
Wrong workspace dataSwitcher on wrong workspaceUse top-bar workspace switcher
Permission denied on saveViewer/Analyst roleElevate role or ask Admin

Best practices

  • Minimum role per person; avoid giving everyone Admin.
  • Remove ex-employees promptly; owners review Account → Sessions.
  • Enable 2FA on owner accounts.
  • Use a separate staging workspace for experiments.
  • Enterprise: enable audit log review in Settings for configuration changes.

Roles reference

RoleUsually can
Workspace OwnerEverything including billing, deletion, AI keys
AdministratorWebsites, config, scans, reports, invites
EditorConsent Setup, scans, most operational pages
AnalystView reports and exports; limited edits
ViewerRead-only dashboards and logs
SupportOperational access per deployment policy

Exact permissions may vary by plan and server configuration—labels appear on Account as your role.

Invite a teammate

  1. Open Settings.
  2. Scroll to Team Permissions.
  3. Enter email and select role (Admin, Analyst, Viewer, Support when available).
  4. Send invite.

Workspace switcher

Users in multiple workspaces use the workspace switcher in the top bar. Switching changes all data: websites, billing, and logs.

Billing ownership

Only owners can upgrade plans, open the Stripe customer portal, and Sync from Stripe on Billing.

Enterprise features

Enterprise plans may include the audit log panel in Settings, OIDC SSO (sales-assisted setup), and shared scanner egress IPs for firewall allowlists.