Manage Members and Permissions
Invite Cribl.Cloud Members, configuring their Permissions at the Organization or Cribl Search level. Learn about the access privileges provided with each Member Permission level.
Manage Invites and Members
From the Organization > Members & Teams page, an Organization’s owner can invite new users to join the Organization, assign access Permissions to new and existing Members, remove pending invites, and remove existing Members.

Invite Members
To invite a new Member:
- On the top bar, select Products, and then select Cribl.
- In the sidebar, select Organization, and then select Members & Teams.
- On the Members & Teams submenu, select Members.
- Select Invite Member to open the page shown below.
- Enter the Email of the new user you want to invite.
- Under Permissions, assign appropriate role on your Organization.
- If you selected the User role, under Workspace Access, define access to specific Workspaces.
Assigning the User role is available on certain plan/license tiers. For details, see Pricing.
- If you selected the Member Permission for any Workspace, additionally select product-level Permissions for that Workspace.
- Select Send Invite to send the invitation.

Respond to Invites
An invited Member receives an email with an Accept Invitation link to either sign into their existing Cribl.Cloud account, or else sign up to create an account and its credentials.
After signing in, they’ll have access to your Organization and Cribl instance at the Permission level you’ve specified.
Organization Member Permissions
You assign Permissions per individual user when you invite them to your Organization as Members, or after they join the Org. Cribl.Cloud does not support globally predefining or assigning group Permissions, as on-prem deployments do.
Permission | User | Admin | Owner |
---|---|---|---|
Log into the system | ✓ | ✓ | ✓ |
Update own Member profile | ✓ | ✓ | ✓ |
View Stream Worker Groups to which you have access | ✓ | ✓ | ✓ |
Admin Access to all Products | ✓ | ✓ | |
View and execute Leader commits | ✓ | ✓ | |
View and modify Global Settings | ✓ | ✓ | |
Manage ACLs (Access Control lists) | ✓ | ✓ | |
View and update SSO settings | ✓ | ✓ | |
View Data Sources and Trust Policies | ✓ | ✓ | |
Manage API Credentials | ✓ | ✓ | |
View and manage Cribl Suite Global Settings | ✓ | ✓ | |
View and manage (provision, update, and delete) Stream Worker Groups | ✓ | ✓ | |
View the Organization’s Billing Dashboards | ✓ | ✓ | |
Download invoices | ✓ | ✓ | |
View Organization Details | ✓ | ✓ | |
Update Organization Details | ✓ | ||
Delete an Organization | ✓ | ||
View Organization Members | ✓ | ✓ | |
Manage (invite, update, delete) Organization Members | ✓ | ✓ | |
Create and delete Lakehouses | ✓ | ||
Link and unlink Lakehouses from Datasets | ✓ |
Each user can have Owner Permissions on multiple Organizations, and each Organization can have multiple users as Owners. However, each user – as defined by their email address – can register only one active Organization, and only if they are not already the Owner of a different Organization.
Cribl.Cloud does not use the earlier access-management model of Local Users and Roles/Policies that is still supported in on-prem Cribl Stream and Edge. Create and configure only Members on Cribl.Cloud applications (Cribl Search and Lake). References elsewhere in Cribl docs to Local Users do not apply to Cribl.Cloud.
Search Member Permissions
You can assign the following Permissions at the Cribl Search product level.
Permission | User | Editor | Admin |
---|---|---|---|
Data, Dashboards, and Libraries | |||
Create, configure, view, and modify Datasets | ✓ | ✓ | |
Create, configure, view, and modify Dataset Providers | ✓ | ✓ | |
Unhide Dataset Provider credentials | ✓ | ||
Create, configure, view, and modify Dashboards | ✓ | ✓ | ✓ |
Create, configure, view, and modify saved and scheduled searches | ✓ | ✓ | ✓ |
Create, configure, view, and modify settings like Datatypes and Event Breakers | ✓ | ✓ | ✓ |
Create, configure, view, modify, and export to lookups | ✓ | ✓ | ✓ |
Create, configure, view, and modify other libraries (Parsers, Regexes, Grok Patterns) | ✓ | ✓ | ✓ |
Create, view, use, import, modify, and export Packs | ✓ | ✓ | |
Access Control and Visibility | |||
Invite other users (Members) to the Workspace | ✓ | ✓ | |
Manage other Members | ✓ | ||
Promote Members to Admins | ✓ | ||
See search history | Only own searches | Only own searches | ✓ |
Search Query Language | |||
export operator | ✓ | ✓ | |
send operator | Only default URL | ✓ | ✓ |
.cancel command | Only own searches | Only own searches | ✓ |
.show queries command | Only own searches | Only own searches | ✓ |
$vt_datasets virtual table | ✓ | ||
$vt_dataset_providers virtual table | ✓ | ||
$vt_jobs virtual table | Only own searches | Only own searches | ✓ |
$vt_lookups virtual table | ✓ | ✓ | ✓ |
$vt_object_list virtual table | ✓ | ||
$vt_object_list_summary virtual table | ✓ | ||
$vt_results virtual table | Only own searches | Only own searches | ✓ |
set statements | Only own searches | Only own searches | ✓ |
.clear options command | Only own options | Only own options | ✓ |
Manage Invites
While an invite is pending, the Members & Teams page offers you these options in the Action column to deal with commonly encountered issues:
- Resend Invite: If your invited Member didn’t receive your invitation email, you can click this button to resend it.
- Copy Invite Link: If emails aren’t getting through at all, click this button to copy and share a URL that will take the invitee directly to the signup page. This target page encapsulates the same identity, Organization, and Permissions you specified in the original email invite.
- Revoke Invite: This is for scenarios where you need to revoke a pending invite. (You sent someone a duplicate invite, or your invitee is spending too much time in outer space to be a productive collaborator, etc.) After clicking this button, you’ll see a confirmation dialog.
After seven days, if an invite has been neither accepted nor revoked, it expires.

Remove Members
To remove a Member from your Organization:
- In the sidebar, select Organization, and then select Members & Teams.
- Select Members, and next to the Member you want to remove, select Remove Member from the Action column.
Users will retain access to any other Cribl.Cloud Organizations on which they are Owners or Members.
Remove SSO Members
If your Organization is using SSO integration, the IDP (identity provider) admin manages Members in the IDP system. When you remove such a Member from the IDP, they will still be left in the Members list in the UI.
After removing the Member from the IDP, you also need to manually delete them from the Members list in the Cribl.Cloud Portal to completely remove them from the UI.