Workspace admin
Workspace admin
Govern your Lightdash organization: roles and access, single sign-on and provisioning, service accounts, and organization-wide settings.
Workspace admin is where organization admins govern Lightdash: who belongs to the organization, what each person can do, how they sign in, and how projects and credentials are managed centrally.
Access control runs on roles, groups, and user attributes. SSO and SCIM connect sign-in and user provisioning to your identity provider. Service accounts and organization credentials let teams automate and connect warehouses without sharing secrets, while organization and project settings cover the rest of day-to-day administration.
Roles and permissions
Custom Roles
Custom roles allow you to create granular permission sets tailored to your organization's specific needs. With custom roles, you can define exactly which scopes (permissions) users should have, giving you fine-grained control over access to Lightdash features and resources.
Groups
Groups are a way to manage access to multiple users at the same time. A user can belong to multiple groups.
User attributes
User attributes provide a way to customise Lightdash charts, dashboards, and other behaviour depending on the user that is logged in. For example, you could only show your sales team members data that are relevant to their region.
SCIM Integration
Service accounts
Service accounts provide a userless alternative to Personal Access Tokens (PATs) when working with the Lightdash CLI or the API. They are created and managed at the organization level, can be assigned granular scopes, and remain valid even if the administrator who created them leaves the organization.
Organization credentials
Organization credentials allow admins to create reusable warehouse credentials at the organization level, making it easier for users to create projects securely.
Managing your organization
Leave or delete your Lightdash organization from the Danger zone in your settings.
Creating multiple projects
With Lightdash, you can have a single organization (e.g. Lightdash), and multiple projects within that organization (e.g. Production, Jaffle Shop, etc.)
Customizing the appearance of your project
You can update the default colors used in your organization's charts so that everything you build is on brand.
Custom email domain
Send Lightdash report emails from your own domain (white-labeled email) instead of a Lightdash address.
Export limits
Override the instance-wide query row and CSV/Excel cell limits on a per-organization basis from your admin settings.
Usage analytics
To understand who is accessing content or running queries in your Lightdash projects, we've built usage analytics to help you track this.
Project compilation history
View the history of your project compilations to track changes, monitor deployments, and troubleshoot compilation issues.
User impersonation
Temporarily view Lightdash as another user to troubleshoot user-specific issues/permissions.
Lightdash support access
Let the Lightdash support team impersonate users in your organization to reproduce issues during a support request.
Instance health
How to keep a Lightdash deployment relevant, governed, and performant.
Set up timezones
Model your warehouse data and configure your project so timezones behave predictably.
SSO
Configure SSO
Set up Single Sign-On providers for your organization from Lightdash admin settings, with per-domain routing, password control, and account linking.
Verified domains
Prove ownership of your organization's domains to control SSO routing in Lightdash.