Skip to main content
Version: 0.0.39

Users

User management in Lakehousecat provides administrators with comprehensive tools to create, configure, and manage individual user accounts. The system ensures secure user onboarding while maintaining flexibility for different organizational needs and access requirements.

Overview​

User accounts represent individual people who access the Lakehousecat platform. Each user has:

  • Unique Identity: Email-based identification and authentication
  • Role Assignment: Specific permissions and capabilities within the system
  • Profile Information: Personal settings and preferences
  • Access History: Activity tracking and audit trails

User Management Access​

Administrator Only

User creation and management is restricted to users with the Administrator role. Only administrators can create new users, modify user roles, or manage user access to the system.

Default Administrator Account​

The Lakehousecat system comes with a pre-configured administrator account that provides initial system access. This default administrator can:

  • Create additional user accounts
  • Assign roles and permissions
  • Configure system settings
  • Manage all aspects of user access

Creating New Users​

Accessing User Management​

  1. Login as Administrator: Sign in with administrator credentials
  2. Navigate to Admin Workspace: Access the administrative interface
  3. Open Access Section: Click on "Access" in the main navigation
  4. Select Users Tab: Click on "Users" to view the user management interface

Individual User Creation​

Step-by-Step Process​

  1. Click the Plus Icon (➕) in the Users listing to start creating a new user
  2. Enter Email Address: Provide the email address that will serve as the user's login identifier
  3. Select User Role: Choose the appropriate role from the available options
  4. Send Invitation: Click "Send Invitation" to initiate the user activation process

Required Information​

  • Email Address: Must be unique and valid

    • Serves as the user's login identifier
    • Used for invitation and password reset communications
    • Cannot be changed after user creation
  • User Role: Determines the user's permissions and access level

    • Pending: Temporary status for users awaiting activation
    • User: Standard user with basic access rights
    • Admin: Administrator with full system access
    • Builder: Advanced user with content creation capabilities
    • Demo: Limited access for demonstration purposes
Role Details

For detailed information about each role and their specific permissions, see the Roles documentation.

Bulk User Import​

For organizations needing to create multiple users simultaneously, Lakehousecat supports CSV-based bulk user import.

CSV Import Process​

  1. Prepare CSV File: Create a spreadsheet with user information
  2. Upload File: Use the CSV import feature in the Users interface
  3. Review and Validate: Confirm user details before processing
  4. Send Invitations: Bulk send activation emails to all new users

CSV File Format​

email,role
john.doe@company.com,User
jane.smith@company.com,Builder
admin.user@company.com,Admin

CSV Requirements:

  • First row must contain headers: email,role
  • Email addresses must be valid and unique
  • Roles must match available system roles exactly
  • Maximum 100 users per import batch

User Activation Process​

Invitation Email​

After clicking "Send Invitation," the system automatically:

  1. Generates Activation Link: Creates a secure, time-limited activation token
  2. Sends Email: Delivers invitation email to the specified address
  3. Sets User Status: Marks user as "Pending" until activation is complete

User Activation Steps​

From the user's perspective:

  1. Receive Invitation Email: Check inbox for activation message
  2. Click Activation Link: Follow the secure link provided in the email
  3. Set Password: Create a secure password meeting system requirements
  4. Complete Profile: Add any required profile information
  5. First Login: Access the system with new credentials

Activation Timeline​

  • Invitation Validity: Activation links expire after 7 days
  • Resend Options: Administrators can resend invitations if needed
  • Account Cleanup: Unactivated accounts are automatically removed after 30 days

User Status Management​

User States​

  • Pending: User invited but not yet activated
  • Active: User has activated account and can access the system
  • Suspended: User account temporarily disabled
  • Inactive: User account permanently disabled

Status Transitions​

Administrators can modify user status:

Pending → Active (user completes activation)
Active → Suspended (administrator action)
Suspended → Active (administrator reactivation)
Active → Inactive (administrator deactivation)

User Profile Management​

Profile Information​

Each user account includes:

  • Basic Information: Name, email, contact details
  • System Preferences: Language, timezone, notification settings
  • Access History: Login history and activity logs
  • Group Memberships: Associated groups and inherited permissions

Administrator Actions​

Administrators can:

  • Edit User Details: Modify name, email, and profile information
  • Change User Roles: Update role assignments as needed
  • Reset Passwords: Generate password reset links for users
  • Manage Group Membership: Add or remove users from groups
  • View Activity History: Monitor user activity and access patterns

User Role Management​

Available Roles​

Pending​

  • Purpose: Temporary status for newly invited users
  • Permissions: No system access until activation
  • Duration: Automatically updated upon user activation

User​

  • Purpose: Standard end-user access
  • Permissions: Basic platform functionality
  • Typical Use: Data consumers, report viewers, basic analytics

Admin​

  • Purpose: Full system administration
  • Permissions: All system functions including user management
  • Typical Use: System administrators, security managers

Builder​

  • Purpose: Advanced content creation
  • Permissions: Model development, dashboard creation, data management
  • Typical Use: Data scientists, analysts, content creators

Demo​

  • Purpose: Limited demonstration access
  • Permissions: Read-only access to sample data and features
  • Typical Use: Prospects, temporary access, training scenarios

Role Assignment Best Practices​

  1. Principle of Least Privilege: Assign the minimum role necessary for the user's function
  2. Regular Reviews: Periodically audit user roles and adjust as needed
  3. Role Progression: Plan for users to advance through roles as they gain experience
  4. Documentation: Maintain records of role assignments and justifications

Security Considerations​

Account Security​

  • Strong Passwords: Enforce password complexity requirements
  • Account Lockout: Protect against brute force attacks
  • Session Management: Secure session handling and timeout policies
  • Multi-Factor Authentication: Enhanced security for sensitive roles

Access Control​

  • Role-Based Access: Users inherit permissions through role assignments
  • Group Integration: Additional permissions through group memberships
  • Audit Logging: Complete tracking of user activities and access patterns

Data Protection​

  • Email Verification: Confirm user identity through email validation
  • Secure Communications: Encrypted invitation and reset emails
  • Privacy Controls: User control over profile information sharing

Troubleshooting​

Common Issues​

User Cannot Activate Account​

  • Check Email Delivery: Verify invitation email reached recipient
  • Link Expiration: Generate new activation link if original expired
  • Email Filters: Check spam/junk folders for invitation email

Login Problems​

  • Password Reset: Use password reset functionality
  • Account Status: Verify user account is active, not suspended
  • Role Permissions: Confirm user has appropriate access rights

Bulk Import Failures​

  • CSV Format: Verify file format matches requirements
  • Duplicate Emails: Ensure all email addresses are unique
  • Invalid Roles: Check that role names match system options exactly

Error Messages​

Common error scenarios and solutions:

ErrorCauseSolution
"Email already exists"Duplicate user accountCheck existing users or use different email
"Invalid role specified"Role name doesn't match system rolesUse exact role names from dropdown
"Invitation expired"Activation link too oldResend invitation from user management
"CSV format error"Malformed import fileCheck CSV format and headers

Best Practices​

User Onboarding​

  1. Welcome Process: Provide clear instructions with invitation emails
  2. Role Documentation: Include role-specific getting started guides
  3. Support Contacts: Provide help desk information for new users
  4. Training Resources: Link to relevant documentation and tutorials

Account Management​

  1. Regular Audits: Review user accounts quarterly for accuracy
  2. Cleanup Procedures: Remove inactive accounts regularly
  3. Role Reviews: Assess and update user roles based on changing responsibilities
  4. Group Alignment: Ensure users are in appropriate groups for their roles

Security Best Practices​

  1. Timely Activation: Monitor and follow up on pending activations
  2. Access Reviews: Regular review of user permissions and access patterns
  3. Incident Response: Procedures for compromised or suspicious accounts
  4. Compliance: Maintain user records for audit and compliance requirements

API Integration​

For programmatic user management, see the User Management API endpoints:

# Create new user
POST /api/users
{
"email": "user@example.com",
"role": "User"
}

# Send activation invitation
POST /api/users/{user-id}/invite

# Update user role
PATCH /api/users/{user-id}
{
"role": "Builder"
}