Access to Device Management is managed in the Users app in the Kio Cloud section of the Launchpad, not within Device Management itself. Each person who needs access must have a user profile and be assigned a Device Management role. An app appears on a user's Kontakt.io Launchpad only if they are assigned a role for it. Device Management roles also govern the Kio Setup Manager mobile app.
Roles are assigned by a user with the User Management Administrator role. See Add a user and Assign roles and access to a user.
What makes up a user's access
- Role — a user is assigned one Primary role (the foundation of their access), plus, optionally, one or more Secondary roles for additional capabilities.
- Device-level access — for the Editor and Viewer roles, an Access Manager (a Secondary role) assigns which specific devices the user can work with.
- Campus access — set in the Users app, it applies across Kio Cloud apps and can limit a user to specific campuses.
Roles
Device Management has two types of roles: Primary and Secondary. To use Device Management and the Kio Setup Manager app, a user needs one Primary role, the foundation of their access. Secondary roles are optional and add control over specific features. Every role can view the Dashboard in the Inventory menu. Some roles apply only to the Kio Setup Manager mobile app, and one legacy role is being phased out — both are listed after the tables.
Primary roles
Assign one Primary role as the foundation of a user's access.
Administrator: All permissions. Ideal for those responsible for managing all aspects of your Kontakt.io device inventory.
Editor All: View and edit all devices in your company — including device configuration settings and virtual attributes (Device Name, Notes, Tags, Deployment Status) — install devices with the Kio Setup Manager, and schedule firmware upgrades. Ideal for those responsible for deploying and maintaining devices.
Editor: The same editing permissions as Editor All, but only for the devices assigned to the user by an Access Manager (a Secondary role).
Viewer All: View-only permissions for all devices and their settings.
Viewer: View-only permissions, limited to the devices assigned to the user by an Access Manager (a Secondary role).
| Permission | Administrator | Editor All | Editor | Viewer All | Viewer |
|---|---|---|---|---|---|
| View devices | Yes | Yes | Yes | Yes | Yes |
| Export devices (Bulk menu) | Yes | Yes | Yes | Yes | Yes |
| Edit device virtual attributes (Device Name, Notes, Tags, Deployment Status) | Yes | Yes | Yes | No | No |
| Edit device configuration settings (including bulk edit via CSV) | Yes | Yes | Yes | No | No |
| Install devices (Kio Setup Manager) | Yes | Yes | Yes | No | No |
| Schedule firmware upgrades (Bulk menu) | Yes | Yes | Yes | No | No |
| Claim Order | Yes | No | No | No | No |
| Import external devices | Yes | No | No | No | No |
| Device Federation (Cisco Spaces) | Yes | No | No | No | No |
| Manage device-level access (Bulk menu) | Yes | No | No | No | No |
| Manage Firmware Upgrade settings | Yes | No | No | No | No |
Secondary roles
Assign a Secondary role when a user needs permissions beyond those of their Primary role.
-
Config Manager: Edit all Tag and Infrastructure device settings, including bulk edits via import. See Update multiple devices with a CSV file (bulk edit).
This is a sensitive role: changing a device's settings from its factory default values can affect how it operates. Edit device settings only when instructed by, or after discussing it with, your Kontakt.io contact.
Firmware Manager: Manage scheduled firmware upgrades to keep devices on the latest firmware version. See Schedule firmware upgrades with Managed Firmware Upgrades.
Inventory Manager: Claim Kontakt.io orders, import third-party devices, and set up Cisco Spaces device federation. Claiming an order adds its devices to Device Management, ready to deploy and install. See Claim and add devices with your Kontakt.io Order ID and Import third-party external devices.
Access Manager: Assign users to specific devices (device-level access). Necessary when your organization restricts users to particular devices. See Manage user device-level access.
| Permission | Config Manager | Firmware Manager | Inventory Manager | Access Manager |
|---|---|---|---|---|
| Edit device configuration settings (including bulk edit via CSV) | Yes | — | — | — |
| Schedule firmware upgrades (Bulk menu) | — | Yes | — | — |
| View Firmware Upgrade settings | — | Yes | — | — |
| Claim Order | — | — | Yes | — |
| Import external devices | — | — | Yes | — |
| Device Federation (Cisco Spaces) | — | — | Yes | — |
| Manage device-level access (Bulk menu) | — | — | — | Yes |
A dash (—) indicates the capability is outside that role's scope. Combine a Primary role with one or more Secondary roles for broader access — for example, Editor All plus Firmware Manager.
Kio Setup Manager mobile roles
These roles apply to the Kio Setup Manager mobile app, so they don't appear in the web permission tables above:
Field Engineer: Assigned only to Kontakt.io staff — the project managers and field engineers managing your deployment. It adds troubleshooting tools (the UAT tests tile) in the Kio Setup Manager app. This role is visible in the Users app but is not assigned to your organization's own users.
Temp. Monitor Installer: Lets a user install and configure Temperature Monitors with the Kio Setup Manager app. On iOS, assign the Device Management Temp. Monitor Installer role; on Android, assign the Temp. Monitor Installer role in the Setup Manager (mobile) app.
Legacy role
- User: A legacy role that grants editing access to assigned devices. Kontakt.io is phasing it out in favor of the roles above — assign a current Primary role instead.
How users and Groups are managed
- Accounts without SSO: a User Management Administrator assigns Device Management roles directly in the Users app. A Managed Group can assign roles and campus access to several users at once.
- Accounts with SSO: users, roles, campus access, and Groups sync from your organization's identity provider and are view-only in the Users app; you change them in the identity provider.
See About Groups.
Roles that live outside Device Management
- User Management Administrator — required to create users and assign Device Management roles, in the Users app.