Team Management
Invite teammates, assign roles, and understand workspace permissions in CookieShift.
Manage who can access your CookieShift workspace, what they can change, and how billing ownership works.
Overview
Team management covers workspace membership: inviting users by email, assigning roles (Owner, Admin, Editor, Analyst, Viewer), switching between workspaces, and restricting billing changes to owners.
Why it matters
Consent configuration and scan data are sensitive. Role-based access limits accidental banner changes, exposes the right reports to analysts, and keeps payment details with owners only.
Setup
- Sign in as Owner or Administrator.
- Open Settings → Team Permissions (or Workspace settings).
- Enter teammate email and select role.
- Send invite — they accept via email link (Accept invite flow).
- Teammate selects the workspace in the header switcher if they belong to multiple.
- Revoke access promptly when someone leaves (remove member or disable account per your policy).
Examples
| Role | Typical use |
|---|---|
| Editor | Day-to-day Consent Setup and Scanner |
| Analyst | Reports and consent log exports only |
| Viewer | Read dashboards for executives |
| Administrator | Everything except billing deletion |
| Owner | Billing, AI keys, workspace deletion |
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Invite not received | Spam filter or wrong email | Resend; verify SMTP in System Health |
| Cannot access Billing | Role is not Owner | Owner upgrades or shares portal link |
| Wrong workspace data | Switcher on wrong workspace | Use top-bar workspace switcher |
| Permission denied on save | Viewer/Analyst role | Elevate role or ask Admin |
Best practices
- Minimum role per person; avoid giving everyone Admin.
- Remove ex-employees promptly; owners review Account → Sessions.
- Enable 2FA on owner accounts.
- Use a separate staging workspace for experiments.
- Enterprise: enable audit log review in Settings for configuration changes.
Roles reference
| Role | Usually can |
|---|---|
| Workspace Owner | Everything including billing, deletion, AI keys |
| Administrator | Websites, config, scans, reports, invites |
| Editor | Consent Setup, scans, most operational pages |
| Analyst | View reports and exports; limited edits |
| Viewer | Read-only dashboards and logs |
| Support | Operational access per deployment policy |
Exact permissions may vary by plan and server configuration—labels appear on Account as your role.
Invite a teammate
- Open Settings.
- Scroll to Team Permissions.
- Enter email and select role (Admin, Analyst, Viewer, Support when available).
- Send invite.
Workspace switcher
Users in multiple workspaces use the workspace switcher in the top bar. Switching changes all data: websites, billing, and logs.
Billing ownership
Only owners can upgrade plans, open the Stripe customer portal, and Sync from Stripe on Billing.
Enterprise features
Enterprise plans may include the audit log panel in Settings, OIDC SSO (sales-assisted setup), and shared scanner egress IPs for firewall allowlists.