Roles and permissions
Cosmic access is three layers. A role at a higher layer can grant access below it. A role at a lower layer never grants access above it.
- Workspace: Admin, Manager, User. Controls which brands a person can see, and who can change billing.
- Project: Admin, Manager, User. Controls which Buckets a person can see inside a brand.
- Bucket: Admin, Developer, Editor, Contributor. Controls what they can do with the content.
Workspace Admin and Manager inherit Project Admin on every Project in that Workspace. Project Admin and Manager inherit Bucket Admin on every Bucket in that Project. A Workspace User has no Project access until they are added to one.
Workspace roles
Set at Workspace > Team.
| Capability | Admin | Manager | User |
|---|---|---|---|
| See every Project | Yes | Yes | Assigned Projects only |
| Add Projects | Yes | Yes | |
| Manage members | Yes | Yes | |
| Usage | Yes | ||
| Settings | Yes | ||
| Billing | Yes | ||
| Transfer a Project in | Yes | Yes |
A Workspace User is added to specific Projects, each with its own Project role.
Project roles
Set at Project > Team. On a Workspace, these are nested under the member's Workspace role.
| Capability | Admin | Manager | User |
|---|---|---|---|
| Access every Bucket | Yes | Yes | Assigned Buckets only |
| Add Buckets | Yes | Yes | |
| Manage members | Yes | Yes | |
| Usage | Yes | ||
| Settings | Yes | ||
| Billing | Yes |
A Project User is given a Bucket role on each Bucket they should reach. They cannot add Buckets.
Bucket roles
Set per Bucket when the Project role is User. These four roles are available on every plan.
| Capability | Admin | Developer | Editor | Contributor |
|---|---|---|---|---|
| View all content | Yes | Yes | Yes | Own Objects only |
| Create and edit content | Yes | Yes | Yes | Own Objects, assigned types, drafts only |
| Publish | Yes | Yes | Yes | |
| Edit Object types | Yes | Yes | ||
| Developer tools | Yes | Yes | ||
| Webhooks | Yes | Yes | ||
| Bucket settings | Yes | Yes | ||
| Team | Yes | |||
| AI agents | Yes | Yes |
Editors can be restricted to drafts, so they edit but cannot publish. Developers and Editors can be granted Bucket settings as an extra permission. Contributors must be assigned one or more Object types; they cannot be given the role until an Object type exists.
AI chat in the dashboard follows the Admin and Developer roles. Generating alt text, images, video, audio, and translations is available to every Bucket role.
What a Contributor can see
Contributors are the most restricted role:
- Scoped to a named list of Object types, so a freelancer can work on the blog and nothing else.
- They see only Objects they created themselves.
- They cannot publish. Saves stay in draft until an Editor, Developer, or Admin publishes them.
That is the usual setup for contractors, guest authors, and anyone who should not see the rest of the Bucket.
How to assign access
- Add the person to the Workspace as Admin, Manager, or User.
- If they are a User, add them to each Project they should reach, as Admin, Manager, or User.
- If they are a Project User, set a Bucket role on each Bucket, and Object types if the role is Contributor.
Admins and Managers at a higher layer skip the steps below them. A Workspace Admin does not need a Project or Bucket role.