DocumentationGetting Started & SetupPart 12 of 13Updated

    Team, Governance and Privacy

    Roles and invitations, the weekly operating cadence that keeps the loop running, human-in-the-loop support, Cogny Shield for personal data, audit trails, and workspace deletion.

    Cogny runs best as a team habit with one accountable owner. This page covers who can do what, the weekly rhythm that keeps tickets flowing, and the controls for data protection and auditability.

    Roles

    Settings → Account → Users → Invite User.

    RoleCan
    OwnerEverything, including granting owner and deleting the workspace
    AdminManage users, settings, billing, integrations
    MemberUse chat, read reports and tickets, act within permissions
    ViewerRead-only
    BillingSee the Billing tab only

    Settings as a whole is visible to owners and admins. Members and viewers use Home, Chat, Reports and Tickets. Give the person who approves tickets at least member access, and the person who connects tools admin.

    Every member can also connect their own AI client to the workspace with their own login.

    The weekly cadence

    The customers who get compounding value run the same simple rhythm:

    1. Monday: the reports land. Emailed to the recipients you selected, before the weekly meeting.
    2. Tuesday: the ticket pass. One person, about an hour. Read the New column, approve, refine or reject with reasons, and check Analysis for finished experiments. Record the discussion with Review Meeting if the team meets; the action items become tickets and the discussion becomes context.
    3. During the week: execution runs itself. Approved tickets execute, pull requests get reviewed and merged by whoever owns the site, and the analysis step reschedules itself when data is thin.
    4. Monthly: ten minutes on context. Update the growth strategy with what changed, check core metrics still measure the right thing, and retire reports nobody reads.

    Give the ticket owner a real mandate. A board where every ticket is "approved to" someone else stalls.

    Human in the loop

    If nobody on your side has the time or the channel expertise for the first months, Cogny's partner agency offers a human-in-the-loop retainer: a consultant who pre-reads the reports and tickets, runs the weekly session, fixes tracking and ad account issues, and updates the strategy as objections surface. Customers typically use it for one or two months while tracking and paid search are cleaned up, then run Cogny themselves. It is a separate, cancellable agreement; ask during onboarding.

    Support channel

    Async support runs in a shared channel: Slack Connect, Discord, or wherever your team already is. Settings → Help & Videos lists the contact for your workspace. Report bugs from the app; they are triaged automatically and reach the team with the context attached.

    Cogny Shield

    Settings → Automation → Cogny Shield (GDPR). Two independent switches:

    • GDPR PII masking replaces personal data in tool results with stable placeholders before it reaches the model, using a Swedish-hosted service, and shows you the original values in chat. Analysis works on the masked data; some precision is lost when the personal data was the signal.
    • MCP cross-server injection scan quarantines instruction-shaped text coming back from an integration (a product description or a support message that tries to instruct the agent) so it cannot steer the agent.

    Both fail closed: if the service is unavailable, the pass does not proceed unmasked. Both are metered lightly.

    Models and data residency

    Cogny does not depend on one model. It continuously tests and evaluates the best model for each purpose in the workflow, on its own benchmark of marketing-analytics problems, and routes each step accordingly. Workspaces that need data to stay in Europe can run on EU-hosted options. Your data stays in your workspace's own Google Cloud project in the EU.

    Audit trail

    • Every write through an integration is recorded in the MCP Write Ledger (Settings → Automation): which tool, which agent or ticket, when, and with what arguments.
    • Every ticket keeps its brief, its execution log, its evaluation and all feedback.
    • Every report keeps its queries.
    • Pull requests are the audit trail for code.

    Deleting a workspace or account

    Settings → Account → Account. Deleting a workspace requires typing a confirmation, and when there are several owners, each must confirm. Deleting your account also schedules any workspaces you alone own.

    Deletion has a seven-day grace period with a Cancel Deletion button. The subscription is set to end at the period end. After the grace period, the workspace's cloud resources are torn down and the data is deleted unattended. Export what you need before you request it.

    Two safeguards: a workspace with a pending deletion cannot buy a new subscription, and if you clearly change your mind (for example by buying a plan for the workspace after requesting deletion), the deletion is held for a human to review rather than executed.

    Reading this with an AI agent? Fetch the raw markdown at /docs/team-governance-and-privacy/index.md or see llms.txt.

    Cogny Cloud
    Ready to set up Cogny Cloud?
    $499/mo with 5,000 credits included, month to month. Setup takes about an hour with us on the call.