Roles and permissions

Cosmic access is three layers. A role at a higher layer can grant access below it. A role at a lower layer never grants access above it.

  1. Workspace: Admin, Manager, User. Controls which brands a person can see, and who can change billing.
  2. Project: Admin, Manager, User. Controls which Buckets a person can see inside a brand.
  3. Bucket: Admin, Developer, Editor, Contributor. Controls what they can do with the content.

Workspace Admin and Manager inherit Project Admin on every Project in that Workspace. Project Admin and Manager inherit Bucket Admin on every Bucket in that Project. A Workspace User has no Project access until they are added to one.

Workspace roles

Set at Workspace > Team.

CapabilityAdminManagerUser
See every ProjectYesYesAssigned Projects only
Add ProjectsYesYes
Manage membersYesYes
UsageYes
SettingsYes
BillingYes
Transfer a Project inYesYes

A Workspace User is added to specific Projects, each with its own Project role.

Project roles

Set at Project > Team. On a Workspace, these are nested under the member's Workspace role.

CapabilityAdminManagerUser
Access every BucketYesYesAssigned Buckets only
Add BucketsYesYes
Manage membersYesYes
UsageYes
SettingsYes
BillingYes

A Project User is given a Bucket role on each Bucket they should reach. They cannot add Buckets.

Bucket roles

Set per Bucket when the Project role is User. These four roles are available on every plan.

CapabilityAdminDeveloperEditorContributor
View all contentYesYesYesOwn Objects only
Create and edit contentYesYesYesOwn Objects, assigned types, drafts only
PublishYesYesYes
Edit Object typesYesYes
Developer toolsYesYes
WebhooksYesYes
Bucket settingsYesYes
TeamYes
AI agentsYesYes

Editors can be restricted to drafts, so they edit but cannot publish. Developers and Editors can be granted Bucket settings as an extra permission. Contributors must be assigned one or more Object types; they cannot be given the role until an Object type exists.

AI chat in the dashboard follows the Admin and Developer roles. Generating alt text, images, video, audio, and translations is available to every Bucket role.

What a Contributor can see

Contributors are the most restricted role:

  • Scoped to a named list of Object types, so a freelancer can work on the blog and nothing else.
  • They see only Objects they created themselves.
  • They cannot publish. Saves stay in draft until an Editor, Developer, or Admin publishes them.

That is the usual setup for contractors, guest authors, and anyone who should not see the rest of the Bucket.

How to assign access

  1. Add the person to the Workspace as Admin, Manager, or User.
  2. If they are a User, add them to each Project they should reach, as Admin, Manager, or User.
  3. If they are a Project User, set a Bucket role on each Bucket, and Object types if the role is Contributor.

Admins and Managers at a higher layer skip the steps below them. A Workspace Admin does not need a Project or Bucket role.