Skip to content

Members

Members lists everyone with access to your tenant, along with any invites still outstanding. It’s a small page you’ll visit twice a quarter: once when someone joins, once when someone leaves.

Creating and revoking invites is restricted to owners and admins. Members and viewers can see who’s in the tenant but can’t change it, and an API key acting on its own behalf can’t invite anyone at all.

Roles

RoleWhat it means
OwnerThe tenant’s first user. Full access, including billing. Can’t be granted by invite — ownership starts at signup and moves by promotion.
AdminEverything except being the owner: invite and revoke people, author schemas, manage connections and keys.
MemberAuthor and query. Can create and edit schemas, connections and files; can’t manage people.
ViewerRead-only. Can open cubes and run queries, and change nothing.

Inviting someone

  1. Enter their work email and pick a role.

  2. Click Invite. The invite is created and the page shows you a one-time accept link.

  3. Send them the link yourself — over Slack, email, however you normally reach them.

  4. They open it, see who invited them and what they’re joining, and accept. If they don’t have a Saiku Cloud login yet they create one at that point and land in your tenant.

Invites expire after 14 days. The Invites table tracks each one as pending, accepted, expired or revoked, and you can Revoke any pending invite that was sent to the wrong address or is no longer wanted.

Inviting an email that already has a live pending invite is refused — revoke the old one first, so there’s never ambiguity about which link is valid.

Removing someone

Removing an existing member isn’t self-serve yet — the members table is read-only in the dashboard today. To take someone’s access away, email support@saiku.bi from an owner or admin address and we’ll do it, usually the same working day.

If it’s urgent — a laptop’s gone missing, a contract ended badly — say so and we’ll treat it as such. In the meantime you can revoke any API keys they minted yourself, which closes the machine-to-machine path immediately.

When a member is removed, their content stays put: cubes they authored remain in the catalog, so nobody’s dashboards break the day they leave.

SSO instead of invites

On Team and above you can authenticate everyone through your own identity provider — Okta, Google Workspace, Entra ID, Auth0, anything WorkOS speaks. With SSO on, people are provisioned on first sign-in and this page becomes a roster rather than an invite desk.

Setup is a short conversation. Email onboarding@saiku.bi and we’ll wire your IdP.

  • Workspaces — grouping schemas within the tenant.
  • Audit log — what each member has actually done.
  • API keys — access for agents rather than people.