Connection sharing & roles

Grant teammates scoped access to a connection — without ever sharing the credential itself.

Last updated

Sharing a connection grants another user the ability to use it through Cocobox at a specific role. The credential never leaves Cocobox — your teammate doesn’t see the password and cannot extract it.

How to share

  1. Open the connection.
  2. Click Share.
  3. Pick a workspace member or paste an email (the invitee will get a link).
  4. Choose a role: read, run, edit, or admin.
  5. (Optional) Set an expiration date.
  6. Save.

Roles in detail

read

The teammate can only run read-only statements: SELECT, SHOW, EXPLAIN, and (on Postgres) WITH … SELECT. Anything else is rejected by Cocobox’s SQL gate before it reaches your database. This includes:

  • INSERT / UPDATE / DELETE / TRUNCATE / MERGE
  • CREATE / ALTER / DROP / RENAME
  • GRANT / REVOKE
  • LOCK / UNLOCK

The gate parses the statement (it’s not a regex) — so disguised attempts (/*comment*/UPDATE …) are caught.

run

A run user can execute saved snippets that were authored by an edit or admin user, but cannot edit ad-hoc SQL. Useful for analysts who need to execute pre-vetted dashboards without write access.

edit

Full read + write SQL editing. Cannot reshare the connection or change credentials.

admin

Everything edit can do, plus:

  • Reshare the connection with other workspace members.
  • Edit credentials (but the new value is still encrypted; the admin doesn’t see the previous value).
  • Delete the connection (soft-delete; recoverable for 30 days).

Revocation

Revoke at any time from the Share dialog or Settings → Connections → Members. Revocation is enforced server-side within ~1 second:

  • Open editor sessions are forced to re-auth on the next query.
  • In-flight queries are not killed — they finish, and the result is delivered, but the next request is rejected.
  • The revoked user sees an “Access revoked” toast and the connection disappears from their sidebar.

Expiration

A shared role can be time-bounded (e.g. expires in 7 days). When the timer hits, the role auto-converts to “no access” and the user sees the same toast as a manual revocation.

Audit

Every share, role change, and revocation is in the audit log. Includes who did it, who was affected, the previous and new role, and the IP.