Invite your team
Add teammates, scope their access per connection, and track every action in the audit log.
Cocobox is built around the assumption that databases are shared. Workspaces, role-scoped sharing, and a full audit log are core, not add-ons.
1. Create or join a workspace
Every account starts in a personal workspace. To work with others, click your avatar → Create workspace, give it a name, then invite teammates by email.
Invitees get a link that, when clicked, joins them to the workspace at the role you chose. Invitations expire in 7 days; you can revoke them at any time.
2. Workspace roles
| Role | Can do |
|---|---|
| Owner | Everything, including billing and deleting the workspace. There is exactly one owner; ownership can be transferred. |
| Admin | Manage members, manage all connections, see full audit log. |
| Member | Create their own connections; access shared connections per the role they were granted. |
| Guest | Read-only access to specifically-shared connections only. Cannot create new connections. |
3. Connection-level sharing
Workspace role and connection-level role are independent. A Member can be granted read-only access to one connection and read-write to another. To share, open the connection → Share → pick a teammate → assign:
| Connection role | Can do |
|---|---|
| Read | SELECT and EXPLAIN only. Auto-blocks any DML/DDL token. |
| Run | Read + execute saved snippets that an editor approved. |
| Edit | Read + write SQL freely. Cannot reshare. |
| Admin | All of the above + reshare + edit credentials. |
Roles are revocable in one click. Revocation is enforced on the server — open editor sessions are forced to re-validate before the next query runs.
4. The audit log
Every connect, query, share, and credential change is recorded in the Audit log (Settings → Audit log). Each entry includes:
- Who — user id, name, email, IP, user-agent.
- What — the action and the affected resource.
- When — ISO timestamp, milliseconds.
- Result — success or the redacted error.
Logs are retained for 365 days on paid plans (90 on trial) and can be exported as JSON or streamed to your SIEM. See Audit log.