---
title: "Manage users and groups"
description: "Reset passwords, control table visibility, and share tables with groups."
canonical: https://ocho.bot/docs/administration/manage-users-and-groups
last_updated: 2026-07-12
---

# Manage users and groups

> Reset passwords, control table visibility, and share tables with groups.

## Reset a user's password

> Who can do this: user administrators (the `user_admin` role). The Users list only appears if user management is provisioned in your workspace — if there's no **Users** item in your sidebar, ask your Ocho contact to set it up.

1. Open the user's record from the Users list. 2. Click **Reset password**. A dialog titled "Reset password for    {email}" opens: "Generate a password or type one. It's set immediately and    emailed to the user — share it with them directly too." 3. The dialog opens in **Generate for me** mode with a policy-compliant    password already generated — use **Copy**, **Regenerate**, or **Hide** as    needed. Switch to **Create my own** to type a password yourself; in that    mode a "Password must include" checklist and a strength meter guide you. 4. **Copy the password before you submit** — after you click **Reset    password** the dialog closes and the password is not shown again. 5. Submit. The password takes effect immediately and is emailed to the user —    you'll see "Password reset — emailed to {email}." If the email can't be    sent, the reset still applies and the message tells you to share the    password directly.

## Share a table with groups

> Who can do this: group administrators (the `group_admin` role), or the table's owner.

Sharing is currently available on Data Manager custom tables. On the table list, a **Share** button appears when row-level security is enabled for your workspace, or when the table's visibility is set to **Restricted**.

1. Click **Share**. The dialog lists the table's current grants (or "Not    shared with any group yet."). 2. Pick a group from **Select a group…**, choose **Can view** or **Can    edit**, then click the **+** (Add group) button. 3. Remove a grant any time with its trash button — removal is immediate, with    no confirmation. 4. Click **Done** to close the dialog.

Members of a granted group get the chosen access to that table; everyone else's access is unchanged.

### Control who can see a table

Custom tables also have a visibility toggle (the table's owner or a table administrator — the `table_admin` role — only) with two settings:

- **Company** — everyone in your company can see the table. This is the

default.

- **Restricted** — only you, table admins, and shared groups can see the

table. Restricting a table is what makes the **Share** button appear in   workspaces without row-level security.

## Good to know

- Groups already granted access are filtered out of the group picker; when

every group has a grant you'll see "No more groups to add."

- In workspaces without row-level security, custom tables default to

**Company** visibility and are visible to the whole organization — no Share   button needed. A **Restricted** table is the exception: it's hidden from   the organization and shared only via group grants.

- Documents, datasets, and chats don't have a Share button today — sharing

applies to Data Manager custom tables only.

- Role assignment itself (giving someone `table_admin`, for example) is done

on the **Roles** tab of the user's record, and requires the `role_admin`   role — `user_admin` lets you open user records and reset passwords, but not   assign roles. See   [Roles and permissions](/docs/administration/roles-and-permissions).

All docs: https://ocho.bot/docs

---

Ocho — AI knowledge orchestration · [Home](https://ocho.bot/) · [Docs](https://ocho.bot/docs) · [Blog](https://ocho.bot/blog) · [About](https://ocho.bot/about) · [Developers](https://ocho.bot/developers) · [Contact](https://ocho.bot/contact) · [llms.txt](https://ocho.bot/llms.txt)
