Goldilocks Docs
Settings

User Management

Invite team members and manage permissions

User Management lets you invite team members, assign roles, and control who has access to your Goldilocks account.

Accessing User Management

  1. Go to Settings
  2. Click Users or Team

User List

View all users in your account:

ColumnDescription
NameUser's display name
EmailLogin email
RolePermission level
StatusActive, Pending, Disabled
Last ActiveLast login date

Inviting Users

Send an Invitation

  1. Click Invite User (or Add Team Member)
  2. Enter the user's email address
  3. Select a role
  4. Optionally add a personal message
  5. Click Send Invite

What Happens Next

  1. User receives email invitation
  2. They click the link to accept
  3. Create their password
  4. Gain access based on assigned role

Pending Invitations

View outstanding invitations:

  • Email address
  • Role assigned
  • Date sent
  • Option to resend or revoke

Resend Invitation

If user didn't receive:

  1. Find the pending invitation
  2. Click Resend
  3. New email sent to same address

Revoke Invitation

To cancel before acceptance:

  1. Find the pending invitation
  2. Click Revoke or Cancel
  3. Link no longer works

User Roles

Admin

Full access to all features:

  • All content management
  • AI agent configuration
  • Widget settings
  • Analytics and insights
  • User management
  • Billing and settings

Who should be Admin: Account owners, managers

Document Manager

Content and moderate access:

  • All content management
  • Approve pending content
  • View analytics
  • Configure escalation
  • Cannot manage billing or users

Who should be Document Manager: Content team leads, senior support

Document Submitter

Limited content access:

  • Create content (pending approval)
  • View own content
  • Basic dashboard access
  • Cannot approve or configure

Who should be Document Submitter: Content contributors, support agents

Managing Existing Users

Change Role

To change a user's role:

  1. Find the user in the list
  2. Click on their row or the edit icon
  3. Select new role
  4. Save changes

Disable User

To remove access without deleting:

  1. Find the user
  2. Click Disable or toggle status
  3. User can no longer log in
  4. Can be re-enabled later

Delete User

To permanently remove:

  1. Find the user
  2. Click Delete or Remove
  3. Confirm deletion

Deleted users cannot be recovered. Use Disable if you might restore access later.

Transfer Ownership

To make someone else the account owner:

  1. Go to account settings
  2. Find Transfer Ownership
  3. Select new owner (must be Admin)
  4. Confirm with your password
  5. Ownership transfers

Role Permissions Detail

PermissionAdminDoc ManagerSubmitter
Create content
Publish content
Approve content
Delete contentOwn only
Configure personas
Configure workflows
Widget settings
View analytics
Manage users
Billing

Team Seats

Seat Limits

Your plan includes a certain number of seats:

  • Free: 1 seat
  • Pro: 5 seats
  • Business: 15 seats
  • Enterprise: Unlimited

At Seat Limit

If you've used all seats:

  1. Remove/disable unused users
  2. Upgrade for more seats
  3. Contact sales for seat add-ons

Counting Seats

What counts as a seat:

  • Active users
  • Pending invitations
  • Disabled users don't count

Security

Password Requirements

Users must have secure passwords:

  • Minimum 8 characters
  • Mix of letters and numbers
  • Special characters recommended

Two-Factor Authentication

If enabled for your account:

  • Users must set up 2FA
  • Required for Admins
  • Optional for other roles

Session Management

Users can manage their sessions:

  • View active sessions
  • Log out of other devices
  • See login history

Best Practices

Use Least Privilege

Assign the minimum role needed:

  • Most users should be Submitters
  • Document Managers for team leads
  • Few Admins (1-2)

Regular Audits

Review users periodically:

  • Remove former employees
  • Disable inactive accounts
  • Verify role appropriateness

Onboard Properly

When adding new users:

  • Explain their role and permissions
  • Provide training resources
  • Set up a buddy for questions

Off-board Securely

When removing users:

  • Disable account immediately
  • Check for shared credentials
  • Review any content they created