Access Management
The Access section is the administrative control center for your Lakehousecat instance. Administrators can monitor the instance license status, manage user accounts and roles, and organize users into groups for efficient sharing.
Admin only: The Access section is only visible to users with the Admin role.
Navigating to Access
- Open the workspace.
- In the left sidebar, click Access.
The Access section contains four tabs:
| Tab | Description |
|---|---|
| Instance | Read-only view of the instance license status and registration details |
| Users | Invite and manage user accounts and roles |
| Groups | Create and manage user groups for sharing |
| Audit Log | Chronological record of all changes made to objects in the instance |
Instance
The Instance tab displays current licensing and registration information for your Lakehousecat instance. All fields are read-only — no configuration can be changed here.
Subscription Status
| Field | Description |
|---|---|
| Subscription Type | The active plan: FREE, STANDARD, PREMIUM, or ENTERPRISE |
| Status | Current subscription state: ACTIVE, TRIALING, PAST_DUE, CANCELED, or EXPIRED |
| User Seats | The number of licensed user seats for this instance |
| License Token Expires | The expiration time of the current license token, shown as remaining time and the exact date |
Instance Registration
| Field | Description |
|---|---|
| Organization Key | The unique key identifying your organization with the Lakehousecat operator |
| Instance ID | The unique identifier for this specific instance |
The license token is automatically renewed by the Lakehousecat operator. Manual token management is not required.
Read-Only Mode
If the license has expired, the instance enters Read-Only Mode. In this state:
- A warning banner is displayed on the Instance tab.
- Only viewing operations are permitted across the entire platform.
- No data sources, models, jobs, or other objects can be created or modified.
- Full functionality is restored when the subscription is renewed.
Users
The Users tab allows administrators to invite new users, manage existing accounts, and assign roles.
User Roles
| Role | Description |
|---|---|
admin | Full administrative access: manages users, groups, provider models, and all workspace resources |
builder | Can create and manage data sources, custom models, jobs, and analytics |
user | Standard user: can chat, create prompts, access analytics shared with them |
pending | Invited but not yet activated |
User Seats and licensing: The number of active users in the instance drives the licensing cost. Monitor the User Seats count on the Instance tab to stay within your subscription limits.
Inviting a New User
- In the Users tab, click the + (Plus) button.
- Enter the user's email address.
- Select the initial role for the user.
- Click Invite to send the invitation.
The user receives an invitation and appears in the list with the pending role until they activate their account.
Managing Users
The user list shows all registered users with their name, email, role, and last activity time.
Changing a User's Role
Click the role badge next to a user's name to cycle through the available roles:
user → admin → builder → pending → user
The role is updated immediately.
Editing a User
Click the pencil icon on a user entry to edit:
- Name
- Password (only if changing — leave blank to keep the current password)
Deleting a User
Click More (⋯) on a user entry and select Delete. A confirmation dialog is shown before the user is permanently removed.
The last remaining admin account cannot be deleted. At least one admin must always exist.
User List Features
| Feature | Description |
|---|---|
| Search | Filter users by name or email |
| Tag Filter | Filter by assigned color tag |
| List / Cards View | Toggle between display modes |
Groups
The Groups tab allows administrators to organize users into named groups. Groups are the primary mechanism for sharing objects — such as chats, models, charts, dashboards, prompts, and job definitions — with multiple users at once.
Creating a Group
- In the Groups tab, click the + (Plus) button.
- Fill in the form.
| Field | Required | Description |
|---|---|---|
| Name | Yes | A descriptive name for the group (e.g., Data Engineering, Finance Team) |
| Description | No | An optional explanation of the group's purpose. Supports voice input. |
| Members | No | Select users to add to the group at creation time. Members can be added or removed later. |
- Click Create to save the group.
Managing Group Members
In the group editor:
- Add members: Search for users by name or email and select them from the available users list.
- Remove members: Click the remove button next to a member in the current members list.
Using Groups for Sharing
When sharing any object (chart, dashboard, prompt, job definition, data source, model), you can select one or more groups in the sharing dialog. All current members of the selected group gain access immediately.
Group membership changes are reflected automatically — adding a user to a group grants them access to all objects currently shared with that group.
Group Actions
Hover over a group entry to access:
| Action | Description |
|---|---|
| Edit (pencil icon) | Opens the group editor to update name, description, and membership |
| More (⋯) | Access additional options: assign color tag, delete |
| Delete | Permanently removes the group. Shared objects are not deleted, but group-based access is revoked. |
Group List Features
| Feature | Description |
|---|---|
| Search | Filter groups by name |
| Tag Filter | Filter by assigned color tag |
| List / Cards View | Toggle between display modes |
Audit Log
The Audit Log tab provides a chronological record of all changes made to objects in the Lakehousecat instance. It is visible to Administrators only.
What is logged
Every significant action is recorded, including:
- Object creation, modification, and deletion (data sources, models, charts, dashboards, job definitions, prompts)
- Approval actions on charts and dashboards
- Sharing and unsharing of objects
- User and group management changes
Reading the Audit Log
Each entry shows:
| Column | Description |
|---|---|
| Timestamp | When the action occurred |
| User | Who performed the action |
| Action | The type of change (e.g., CREATE, UPDATE, DELETE, APPROVE, SHARE) |
| Entity Type | The type of object that was changed |
| Entity Name | The name of the affected object |
Use the Audit Log to trace unexpected changes, verify approval workflows, and maintain compliance records.
Best Practices
- Assign the minimum necessary role: Start users with the
userrole and promote tobuilderoradminonly when needed. - Use groups for team sharing: Instead of sharing objects with individual users one at a time, create a group per team and share with the group. This makes access management much easier as membership changes.
- Monitor User Seats: Keep the active user count within your licensed seat count. The Instance tab shows the current
User Seatsvalue. - Review pending users: Periodically check for users stuck in the
pendingstate — they may need a new invitation or have an incorrect email address. - Name groups clearly: Use names that reflect team or functional boundaries (e.g.,
Analytics Team,Sales Managers,Developers) to make sharing dialogs self-explanatory.