Managing users and entitlements
This guide covers the full user lifecycle in the CloudQuant Data Liberator admin portal — from onboarding a new account to assigning and revoking dataset access.Prerequisites
- Super Admin role for creating users, editing details, assigning entitlements, and deactivating users
- Admin or Super Admin role to add existing user accounts to the permissions system
User lifecycle
Creating a new user
Super Admins can create a brand-new account directly from the Users page.1
Open Create User
Click Create User in the top-right of the Users page.
2
Enter account details
Fill in the required fields:
- Username — unique login identifier
- First name and Last name
- Company — select an existing company or type a new one
- Password — minimum 8 characters; use the generate button for a secure password (not required when using invite-via-email)
3
Submit
Click Create. The platform account is created. Use Add Users (below) to enroll the account in the Liberator permissions system if it does not appear automatically.
Invite via email
In Liberator 2.3 and later, Super Admins can provision users without sharing temporary passwords out of band.1
Enable invite on Create User
Open Create User and turn on Invite via email.
2
Enter profile details
Provide username, email, name, and company as usual. Liberator sends the invite to the email address you enter.
3
User completes setup
The recipient opens the invite link, verifies their email, and sets their own password. Liberator requires a password change on first login for newly invited accounts.
Send a password-reset email
From the Users table Actions menu, select Send reset email to trigger a self-service password reset for an existing account. Use this when a user cannot sign in and you do not want to set a temporary password yourself.Adding users to Liberator
Before a user can receive dataset entitlements, their account must exist in the Liberator permissions system. Use Add Users to enroll accounts that are not yet active in Liberator.1
Open Add Users
Click Add Users on the Users page.
2
Select from Available Users
The Available Users tab lists enabled accounts that are not yet in the permissions system. Use the column filters to search by name or email, select one or more users, then click Add.
3
Re-activate deactivated users (optional)
The Deactivated Users tab lists previously deactivated accounts. Select users and click Re-activate to restore their Liberator enrollment. You will still need to re-assign entitlements if they were removed during deactivation.
Editing user details
Super Admins can update profile information and platform roles from the Users table.1
Open the edit dialog
In the Actions column, click the edit icon for the target user.
2
Update fields
Modify any of:
- First name, last name, email, company
- User Role —
User,Admin, orSuper Admin(you can only assign roles at or below your own level) - Password — optionally set a temporary password (copied to clipboard on save)
3
Save
Click Save Changes.
Assigning dataset entitlements
Entitlements control which datasets a user can query. Super Admins manage entitlements through the Data Permissions dialog.1
Open Data Permissions
In the Users table Actions column, click the data-permissions icon for the target user.
2
Select datasets and groups
The permissions table lists all datasets and dataset groups. Check the rows you want to grant:
- Dataset rows grant access to a single dataset
- Group rows grant access to every dataset in that dataset group
3
Save changes
Click Save Changes and confirm. Changes take effect immediately for the user’s next query.
Inherited (locked) datasets
If a user has connection-level entitlements, all datasets in that connection are automatically included. These datasets:- Appear with a lock icon in the permissions table
- Show as (locked) on their selection pill
- Cannot be individually deselected until the connection entitlement is removed
Viewing a user’s access
Click the View action on any user to open a read-only summary of their connections, datasets, groups, and role. Super Admins also see a JSON tab with the raw permissions payload.Removing entitlements
To revoke dataset or group access:- Open Data Permissions for the user.
- Deselect the dataset or group row in the table, or click the remove button on its pill.
- Click Save Changes.
Deactivating users
Deactivation removes a user from the active Liberator permissions system. The user account is disabled and the user’s permissions row is deleted on the backend.Single user
1
Deactivate from the Users table
Click the delete icon in the Actions column, or open Data Permissions and click the trash icon in the modal header.
2
Confirm
Confirm the deactivation. The user moves to the Deactivated Users tab in the Add Users dialog.
Bulk deactivation
Super Admins can deactivate multiple users at once:- Select users using the checkboxes in the rightmost column.
- Click Deactivate Selected.
- Type
DEACTIVATEto confirm.
You cannot deactivate your own account. Bulk deactivation requires Super Admin role.
Re-activating users
- Click Add Users on the Users page.
- Switch to the Deactivated Users tab.
- Select the users to restore and click Re-activate.
- Re-assign any dataset entitlements and fine-grained rules that were removed during deactivation.

