Users
User management in Lakehousecat provides administrators with comprehensive tools to create, configure, and manage individual user accounts. The system ensures secure user onboarding while maintaining flexibility for different organizational needs and access requirements.
Overview
User accounts represent individual people who access the Lakehousecat platform. Each user has:
- Unique Identity: Email-based identification and authentication
- Role Assignment: Specific permissions and capabilities within the system
- Profile Information: Personal settings and preferences
- Access History: Activity tracking and audit trails
User Management Access
User creation and management is restricted to users with the Administrator role. Only administrators can create new users, modify user roles, or manage user access to the system.
Default Administrator Account
The Lakehousecat system comes with a pre-configured administrator account that provides initial system access. This default administrator can:
- Create additional user accounts
- Assign roles and permissions
- Configure system settings
- Manage all aspects of user access
Creating New Users
Accessing User Management
- Login as Administrator: Sign in with administrator credentials
- Navigate to Admin Workspace: Access the administrative interface
- Open Access Section: Click on "Access" in the main navigation
- Select Users Tab: Click on "Users" to view the user management interface
Individual User Creation
Step-by-Step Process
- Click the Plus Icon (➕) in the Users listing to start creating a new user
- Enter Email Address: Provide the email address that will serve as the user's login identifier
- Select User Role: Choose the appropriate role from the available options
- Send Invitation: Click "Send Invitation" to initiate the user activation process
Required Information
-
Email Address: Must be unique and valid
- Serves as the user's login identifier
- Used for invitation and password reset communications
- Cannot be changed after user creation
-
User Role: Determines the user's permissions and access level
- Pending: Temporary status for users awaiting activation
- User: Standard user with basic access rights
- Admin: Administrator with full system access
- Builder: Advanced user with content creation capabilities
- Demo: Limited access for demonstration purposes
For detailed information about each role and their specific permissions, see the Roles documentation.
Bulk User Import
For organizations needing to create multiple users simultaneously, Lakehousecat supports CSV-based bulk user import.
CSV Import Process
- Prepare CSV File: Create a spreadsheet with user information
- Upload File: Use the CSV import feature in the Users interface
- Review and Validate: Confirm user details before processing
- Send Invitations: Bulk send activation emails to all new users
CSV File Format
email,role
john.doe@company.com,User
jane.smith@company.com,Builder
admin.user@company.com,Admin
CSV Requirements:
- First row must contain headers:
email,role - Email addresses must be valid and unique
- Roles must match available system roles exactly
- Maximum 100 users per import batch
User Activation Process
Invitation Email
After clicking "Send Invitation," the system automatically:
- Generates Activation Link: Creates a secure, time-limited activation token
- Sends Email: Delivers invitation email to the specified address
- Sets User Status: Marks user as "Pending" until activation is complete
User Activation Steps
From the user's perspective:
- Receive Invitation Email: Check inbox for activation message
- Click Activation Link: Follow the secure link provided in the email
- Set Password: Create a secure password meeting system requirements
- Complete Profile: Add any required profile information
- First Login: Access the system with new credentials
Activation Timeline
- Invitation Validity: Activation links expire after 7 days
- Resend Options: Administrators can resend invitations if needed
- Account Cleanup: Unactivated accounts are automatically removed after 30 days
User Status Management
User States
- Pending: User invited but not yet activated
- Active: User has activated account and can access the system
- Suspended: User account temporarily disabled
- Inactive: User account permanently disabled
Status Transitions
Administrators can modify user status:
Pending → Active (user completes activation)
Active → Suspended (administrator action)
Suspended → Active (administrator reactivation)
Active → Inactive (administrator deactivation)
User Profile Management
Profile Information
Each user account includes:
- Basic Information: Name, email, contact details
- System Preferences: Language, timezone, notification settings
- Access History: Login history and activity logs
- Group Memberships: Associated groups and inherited permissions
Administrator Actions
Administrators can:
- Edit User Details: Modify name, email, and profile information
- Change User Roles: Update role assignments as needed
- Reset Passwords: Generate password reset links for users
- Manage Group Membership: Add or remove users from groups
- View Activity History: Monitor user activity and access patterns
User Role Management
Available Roles
Pending
- Purpose: Temporary status for newly invited users
- Permissions: No system access until activation
- Duration: Automatically updated upon user activation
User
- Purpose: Standard end-user access
- Permissions: Basic platform functionality
- Typical Use: Data consumers, report viewers, basic analytics
Admin
- Purpose: Full system administration
- Permissions: All system functions including user management
- Typical Use: System administrators, security managers
Builder
- Purpose: Advanced content creation
- Permissions: Model development, dashboard creation, data management
- Typical Use: Data scientists, analysts, content creators
Demo
- Purpose: Limited demonstration access
- Permissions: Read-only access to sample data and features
- Typical Use: Prospects, temporary access, training scenarios
Role Assignment Best Practices
- Principle of Least Privilege: Assign the minimum role necessary for the user's function
- Regular Reviews: Periodically audit user roles and adjust as needed
- Role Progression: Plan for users to advance through roles as they gain experience
- Documentation: Maintain records of role assignments and justifications
Security Considerations
Account Security
- Strong Passwords: Enforce password complexity requirements
- Account Lockout: Protect against brute force attacks
- Session Management: Secure session handling and timeout policies
- Multi-Factor Authentication: Enhanced security for sensitive roles
Access Control
- Role-Based Access: Users inherit permissions through role assignments
- Group Integration: Additional permissions through group memberships
- Audit Logging: Complete tracking of user activities and access patterns
Data Protection
- Email Verification: Confirm user identity through email validation
- Secure Communications: Encrypted invitation and reset emails
- Privacy Controls: User control over profile information sharing
Troubleshooting
Common Issues
User Cannot Activate Account
- Check Email Delivery: Verify invitation email reached recipient
- Link Expiration: Generate new activation link if original expired
- Email Filters: Check spam/junk folders for invitation email
Login Problems
- Password Reset: Use password reset functionality
- Account Status: Verify user account is active, not suspended
- Role Permissions: Confirm user has appropriate access rights
Bulk Import Failures
- CSV Format: Verify file format matches requirements
- Duplicate Emails: Ensure all email addresses are unique
- Invalid Roles: Check that role names match system options exactly
Error Messages
Common error scenarios and solutions:
| Error | Cause | Solution |
|---|---|---|
| "Email already exists" | Duplicate user account | Check existing users or use different email |
| "Invalid role specified" | Role name doesn't match system roles | Use exact role names from dropdown |
| "Invitation expired" | Activation link too old | Resend invitation from user management |
| "CSV format error" | Malformed import file | Check CSV format and headers |
Best Practices
User Onboarding
- Welcome Process: Provide clear instructions with invitation emails
- Role Documentation: Include role-specific getting started guides
- Support Contacts: Provide help desk information for new users
- Training Resources: Link to relevant documentation and tutorials
Account Management
- Regular Audits: Review user accounts quarterly for accuracy
- Cleanup Procedures: Remove inactive accounts regularly
- Role Reviews: Assess and update user roles based on changing responsibilities
- Group Alignment: Ensure users are in appropriate groups for their roles
Security Best Practices
- Timely Activation: Monitor and follow up on pending activations
- Access Reviews: Regular review of user permissions and access patterns
- Incident Response: Procedures for compromised or suspicious accounts
- Compliance: Maintain user records for audit and compliance requirements
API Integration
For programmatic user management, see the User Management API endpoints:
# Create new user
POST /api/users
{
"email": "user@example.com",
"role": "User"
}
# Send activation invitation
POST /api/users/{user-id}/invite
# Update user role
PATCH /api/users/{user-id}
{
"role": "Builder"
}