Skip to main content
Version: Next

Access Management

The Access section is the administrative control center for your Lakehousecat instance. Administrators can monitor the instance license status, manage user accounts and roles, and organize users into groups for efficient sharing.

Admin only: The Access section is only visible to users with the Admin role.


  1. Open the workspace.
  2. In the left sidebar, click Access.

The Access section contains four tabs:

TabDescription
InstanceRead-only view of the instance license status and registration details
UsersInvite and manage user accounts and roles
GroupsCreate and manage user groups for sharing
Audit LogChronological record of all changes made to objects in the instance

Instance​

The Instance tab displays current licensing and registration information for your Lakehousecat instance. All fields are read-only — no configuration can be changed here.

Subscription Status​

FieldDescription
Subscription TypeThe active plan: FREE, STANDARD, PREMIUM, or ENTERPRISE
StatusCurrent subscription state: ACTIVE, TRIALING, PAST_DUE, CANCELED, or EXPIRED
User SeatsThe number of licensed user seats for this instance
License Token ExpiresThe expiration time of the current license token, shown as remaining time and the exact date

Instance Registration​

FieldDescription
Organization KeyThe unique key identifying your organization with the Lakehousecat operator
Instance IDThe unique identifier for this specific instance

The license token is automatically renewed by the Lakehousecat operator. Manual token management is not required.

Read-Only Mode​

If the license cannot be validated — for example when the instance cannot reach the licensing service — the instance enters Read-Only Mode. In this state:

  • A Read-Only Mode Active warning is displayed on the Instance tab (there is no global banner on other pages).
  • Only viewing operations are permitted across the entire platform.
  • No data sources, models, jobs, or other objects can be created or modified.
  • Full functionality is restored as soon as the license can be validated again.

A paid subscription that is no longer paid — an overdue payment, a cancellation, or a termination — does not lead to Read-Only Mode: the instance continues on the Free Tier, where only the initial administrator can sign in and nothing is deleted. Once the subscription is active again, the limits of your plan return with the next license renewal.

The warning names one of three reasons:

ReasonMeaningWhat helps
License expiredThe subscription has lapsedRenew the subscription
No license foundThe instance has no license tokenContact your administrator
License could not be verifiedThe license token was issued for a different instance, or its chain of trust cannot be verifiedContact your administrator — renewing does not resolve this

Users​

The Users tab allows administrators to invite new users, manage existing accounts, and assign roles.

User Roles​

RoleDescription
adminFull administrative access: manages users, groups, provider models, and all workspace resources
builderCan create and manage data sources, custom models, jobs, and analytics
userStandard user: can chat, create prompts, access analytics shared with them
pendingInvited but not yet activated

User Seats and licensing: The number of active users in the instance drives the licensing cost. Monitor the User Seats count on the Instance tab to stay within your subscription limits.

Inviting a New User​

  1. In the Users tab, click the + (Plus) button.
  2. Enter the user's email address.
  3. Select the initial role for the user.
  4. Click Invite to send the invitation.

The user receives an invitation and appears in the list with the pending role until they activate their account.

Managing Users​

The user list shows all registered users with their name, email, role, and last activity time.

Changing a User's Role​

Click the role badge next to a user's name to cycle through the available roles:

user → admin → builder → pending → user

The role is updated immediately.

Editing a User​

Click the pencil icon on a user entry to edit:

  • Name
  • Email
  • Password (only if changing — leave blank to keep the current password)

Deleting a User​

Click More (⋯) on a user entry and select Delete. A confirmation dialog is shown before the user is permanently removed.

The last remaining admin account cannot be deleted. At least one admin must always exist.

User List Features​

FeatureDescription
SearchFilter users by name or email
Tag FilterFilter by assigned color tag
List / Cards ViewToggle between display modes

Groups​

The Groups tab allows administrators to organize users into named groups. Groups are the primary mechanism for sharing objects — such as chats, models, charts, dashboards, prompts, and job definitions — with multiple users at once.

Creating a Group​

  1. In the Groups tab, click the + (Plus) button.
  2. Fill in the form.
FieldRequiredDescription
NameYesA descriptive name for the group (e.g., Data Engineering, Finance Team)
DescriptionNoAn optional explanation of the group's purpose. Supports voice input.
MembersNoSelect users to add to the group at creation time. Members can be added or removed later.
  1. Click Create to save the group.

Managing Group Members​

In the group editor:

  • Add members: Search for users by name or email and select them from the available users list.
  • Remove members: Click the remove button next to a member in the current members list.

Using Groups for Sharing​

When sharing any object (chart, dashboard, prompt, job definition, data source, model), you can select one or more groups in the sharing dialog. All current members of the selected group gain access immediately.

Group membership changes are reflected automatically — adding a user to a group grants them access to all objects currently shared with that group.

Group Actions​

Hover over a group entry to access:

ActionDescription
Edit (pencil icon)Opens the group editor to update name, description, and membership
More (⋯)Access additional options: assign color tag, delete
DeletePermanently removes the group. Shared objects are not deleted, but group-based access is revoked.

Group List Features​

FeatureDescription
SearchFilter groups by name
Tag FilterFilter by assigned color tag
List / Cards ViewToggle between display modes

Audit Log​

The Audit Log tab provides a chronological record of all changes made to objects in the Lakehousecat instance. It is visible to Administrators only.

What is logged​

Every significant action is recorded, including:

  • Object creation, modification, and deletion (data sources, models, charts, dashboards, job definitions, prompts)
  • Approval actions on charts and dashboards
  • Sharing and unsharing of objects
  • User and group management changes

Reading the Audit Log​

Each entry shows:

ColumnDescription
TimestampWhen the action occurred
UserWho performed the action
ActionThe type of change (e.g., CREATE, UPDATE, DELETE, APPROVE, SHARE)
Entity TypeThe type of object that was changed
Entity NameThe name of the affected object

Use the Audit Log to trace unexpected changes, verify approval workflows, and maintain compliance records.


Best Practices​

  • Assign the minimum necessary role: Start users with the user role and promote to builder or admin only when needed.
  • Use groups for team sharing: Instead of sharing objects with individual users one at a time, create a group per team and share with the group. This makes access management much easier as membership changes.
  • Monitor User Seats: Keep the active user count within your licensed seat count. The Instance tab shows the current User Seats value.
  • Review pending users: Periodically check for users stuck in the pending state — they may need a new invitation or have an incorrect email address.
  • Name groups clearly: Use names that reflect team or functional boundaries (e.g., Analytics Team, Sales Managers, Developers) to make sharing dialogs self-explanatory.