Appearance
Service account Preview
A service account is an account that is independent of any user. Users who are allowed to use it can switch to it. While switched, actions use the service account's permissions, and notebooks and other resources you create belong to the service account.
INFO
This feature is in preview. To request access, contact Codatum support.
Creating and managing service accounts
Only a Workspace Owner can create and manage service accounts.
- Open the global nav > Workspace settings > Service Accounts.
- Select Create service account and specify Name / Workspace role / Groups.
To edit, suspend, or delete a service account after you create it, use the menu on each row of the list (Management menu actions).
Managing who can switch
Only a Workspace Owner can manage who can switch.
- Open the global nav > Workspace settings > Service Accounts.
- From the menu of the service account, select Manage users.
- Add users or groups to Users.
Who can switch
Users added in Managing who can switch and Workspace Owners can switch to a service account. If there's no service account you can switch to, Service accounts isn't shown in the avatar icon menu.
- If you add a group, users who are added to that group later can also switch.
- A Workspace Owner can switch without being added as a user.
- Workspace guests can't switch, even if they're added as users.
Switching to a service account
- Open the avatar icon at the bottom of the global nav > Service accounts.
- Select the service account to switch to.
After you switch, the workspace top page opens, and the avatar icon and name change to those of the service account.
Returning to your account
- Select the avatar icon at the bottom of the global nav > Return to my account.
Management menu actions
The menu on each row of the list has the following actions.
| Action | Description |
|---|---|
| Edit | Changes the name, workspace role, and groups. |
| Manage users | Sets the users and groups that can switch to the service account (Managing who can switch). |
| Suspend / Resume | You can't switch to a suspended service account. |
| Delete | You can't undo a deletion. The service account's Private folder (including the notebooks and folders within it) is also deleted, including items created by users who switched to it. |
Scope of a switch
A switch applies to the browser tab where you switched. It carries over to new tabs opened from that tab (for example, from quick search) and to duplicated tabs. Other tabs stay on your account.
Service account permissions
What you can do as a service account depends on its workspace role, the groups it belongs to, and the permissions granted to it on each resource. The permissions of the user who switched aren't used.
- The workspace role can be Editor, Viewer, or Guest. A service account can't be an Owner.
- A guest service account can't belong to groups. If you change a service account to Guest, it's removed from its groups.
- In the sharing and permission settings of each resource, a Workspace Owner can select a service account and grant it permissions in the same way as a user. You can't select a suspended service account.
Applying removal, suspension, and deletion
After you remove a user from a service account, suspend the service account, or delete it, a user who is currently switched might still be able to act as the service account for up to 1 hour (Limits).
However, an open notebook editing screen might let you keep editing beyond 1 hour while it stays open.
Records of actions while switched
Resources such as notebooks that you create or update while switched are treated as created or updated by the service account. The audit log also records these actions as actions of the service account.
Comments and reactions are shown as posted by the user who switched, not by the service account.
AI agent sessions
All users who can switch to a service account can view the AI agent sessions started with that service account, even if the sessions aren't shared.
- Only the user who started a session can operate it. Other users see (user name)(service account name) started this session (view only).
- Started by me filters the session list. It's on by default, so only the sessions you started are shown.
- Routines that you create while switched run as the service account. All users who can switch can only view the sessions those runs create.
Information shared among users who can switch
Information tied to a service account is shared by all users who can switch to it.
- The Private folder is available to service accounts whose workspace role is Editor, and all users who can switch can access it. While switched, it shows Users who can switch to this service account have access.
- Stars, recently viewed items, and the Created by me tab of notebooks are per service account.
- AI agent pins, memory, and settings are per service account.
Features unavailable while switched
The following features are tied to the individual user, so they're hidden or unavailable while switched.
| Feature | Description |
|---|---|
| Account settings | Account settings, theme switching, and language switching in the avatar menu are hidden. |
| Workspace settings | When you open them, you're asked to return to your account. |
| Other workspaces | You can only open the workspace where you switched. You also can't accept workspace invitations. |
| Notifications | Notifications are hidden. |
| Workflows | Workflow pages are hidden. The AI agent doesn't operate workflows either. |
| Guest invitations from reports | Inviting guests on a report is hidden. You can't invite guests, view invited guests, or remove their permissions. |
| Connector authentication | You can't connect personal-authentication connectors. |
| AI agent feedback | Send feedback is hidden. |
If the service account is shown as unavailable
Service Account is unavailable is shown in any of the following cases.
- You were removed from the service account's users.
- Your workspace role was changed to Guest.
- You were a Workspace Owner who wasn't added as a user, and your workspace role was changed from Owner.
- The service account was suspended or deleted.
- The service account lost access to the workspace.
- Select Return to my account.
- To switch again, ask a Workspace Owner to check the service account's status and who can switch to it.