
Tabs
The user management screen has four tabs.| Tab | Description |
|---|---|
| Overview | View, add, edit, delete individual users |
| Groups | Create and manage permission groups |
| Organizations | Manage organizational units based on Entra ID sync (see Organization Management) |
| Inquiries | Receive and respond to user inquiries |
User List
View and Search Users
Users appear as a table with these columns.| Column | Description |
|---|---|
| Name | User display name |
| Sign-in email address | |
| Role | Admin, User, Pending |
| OAuth ID | External authentication ID for SSO |
| Last activity | Most recent access time |
| Joined | Account creation date |
- Real-time search by name or email
- Sort by name, joined date, or last activity
User Roles
Cloosphere has three roles.| Role | Description | Admin Panel | Workspace | Chat |
|---|---|---|---|---|
| Admin | Full management permission | Full access | Full access | Full access |
| User | Regular user | Per group | Per group | Per group |
| Pending | Awaiting approval | No access | No access | No access |
Super Admin (SA)
New feature — Designate one Admin as Super Admin (SA).
| Item | Description |
|---|---|
| Target | Admin role users only |
| How to assign | Click Set as SA in the user edit modal |
| Display | SA badge shown in the user list |
| Effect | The admin’s email is shown on the account activation pending screen |
Only 1 SA can be designated. Designating a new user as SA auto-removes the existing one. Only Admins can designate SA.
Changing Roles

You can’t change your own role. The first user (First User)‘s role also can’t be changed.
Adding and Editing Users
Adding a User
Click the + icon (tooltip: “Add user”) to manually create a user.| Field | Description | Required |
|---|---|---|
| Sign-in email address | ✓ | |
| Name | Display name | ✓ |
| Password | Initial password | ✓ |
| Role | Admin / User / Pending | ✓ |
Editing a User
Click the user’s name or thumbnail, or the edit button on the row, to open the edit modal. Editable items:- Name
- Role
- Profile image URL
- New password
- Member groups — view groups the user belongs to and add/remove
- Member organizational units (OU) — read-only display of the user’s OU tree (Entra/Google Workspace sync result)
Organizational units are shown read-only in the user edit screen. OU membership is determined by external IdP sync — to modify directly, change IdP sync settings in Organization Management.
Deleting a User
User Chats
Admins can view a user’s chat list. Click the Chats button on the user row.Usage Limits
Set per-user daily token usage limits. Set Daily token limit in the user edit screen.| Setting | Description |
|---|---|
| Daily token limit | Maximum tokens usable per day (0 = unlimited) |
| Daily usage | Tokens used so far (read-only) |
Usage limits can be set at four levels — global, user, group, organization. When set at multiple levels, the most permissive (highest) value applies.
Group Management
Groups bundle users for unified permission management. Design groups by department, role, project, etc., to match your organization.Why Groups?
| Per-user | Per-group |
|---|---|
| Set permissions per user individually | Set once on the group, applies to everyone |
| Edit one by one when changing | Edit only the group setting |
| Becomes complex as users grow | Scales systematically |
Creating a Group
Group Permission Settings
Configure detailed permissions per group. All permissions are split into 4 levels.
Permission Levels
| Level | Description |
|---|---|
| None | Cannot access the feature |
| Access | View list (no detail access) |
| Read | View list + view details |
| Write | View + create/edit/delete |
Workspace permissions detail
Workspace permissions detail
| Permission | None | Access | Read | Write |
|---|---|---|---|---|
| Agents | No access | List only | View detail | Create/edit |
| Knowledge Base | No access | List only | View detail | Create/edit |
| Prompts | No access | List only | View detail | Create/edit |
| Tools | No access | List only | View detail | Create/edit |
| Database | No access | List only | View detail | Create/edit |
| Glossary | No access | List only | View detail | Create/edit |
| Guardrails | No access | List only | View detail | Create/edit |
| Flow access | No access | List only | View detail | Create/edit |
Admin permissions detail
Admin permissions detail
You can delegate parts of admin features to regular users.
| Permission | None | Access | Read | Write |
|---|---|---|---|---|
| User management | No access | View user list | View detail | Create/edit/delete |
| Settings access | No access | View settings list | View setting values | Change settings |
| Evaluations | No access | View evaluation list | View detail | Change settings |
| Monitoring | No access | View monitoring | View detail | — |
Sharing/Chat/Feature permissions detail
Sharing/Chat/Feature permissions detail
Default Permissions
Set default permissions applied to users not in any group. Click Default Permissions at the top of the Groups tab.Inquiry Management
Receive and respond to user inquiries to admins.Sending User Inquiries
Regular users click Contact Admin in the bottom sidebar menu to send inquiries.
| Type | Subtype | Description |
|---|---|---|
| Usage limit | Limit increase, limit check | Token limit related |
| Feature | Chat, agents, KBs, databases, tools | Feature usage |
| Bug | Chat error, agent error, upload error, etc. | Error reports |
| Account | Permission request, account issue | Account/permission related |
| Other | Improvement, others | Other inquiries |
Handling Admin Inquiries
Manage received inquiries in Admin > Users > Inquiries tab.
- Kanban view
- List view
Drag cards across status columns (Open, In Progress, Resolved, Closed) to change status.
Best Practices
Role management principles
Role management principles
- Minimize Admins — Designate only essential users as admins
- Use Pending — Set new sign-ups to Pending and approve after review
- Periodic review — Periodically delete or deactivate (Pending) departed user accounts
Group design strategy
Group design strategy
- Department-based — Per-department groups (Marketing, Engineering, Sales, etc.)
- Role-based — Per-rank groups (Manager, Senior, Junior, etc.)
- Project-based — Project participant groups (temporary)
Security recommendations
Security recommendations
- Least privilege — Grant only minimum permissions needed for the job
- Group-first — Prefer group permissions over individual user permissions
- Periodic audit — Periodically review permission settings and revoke unnecessary
FAQ
A user forgot their password
A user forgot their password
Admin can set a new password in user edit. With SSO (Entra ID), contact your company’s IT department.
How do I let only specific users use a specific agent?
How do I let only specific users use a specific agent?
In the agent edit screen’s Access settings, specify the group or organization. Set visibility to “Private” and add the allowed groups.
How do I handle departed user accounts?
How do I handle departed user accounts?
Either delete the account or change the role to Pending to deactivate. Deletion also removes chat history — to preserve history, prefer Pending.
