Access to Staff Safe is managed in the Users app in the Kio Cloud section of the Launchpad, not within Staff Safe itself. Each person who needs access must have a user profile and be assigned a Staff Safe role. An app appears on a user's Kontakt.io Launchpad only if they are assigned a role for it.
User profiles and role assignments are managed by a user with the User Management Administrator role. For accounts without single sign-on (SSO), administrators assign roles directly in the Users app. For accounts with SSO, user profiles their assigned app roles and campus access come from your identity provider and are view-only in the Users app. See Add a user and Assign roles and access to a user.
What makes up a user's access
- Role controls what a user can do — see the roles below.
- Campus access determines which campuses a user has access to. A user can be restricted to specific campuses in the Users app or through your SSO identity provider.
Roles and campus access can also be assigned through a Group in the Users app, so several users inherit the same access at once. (A Users-app Group is not the same as a Staff Safe Staff Group, which organizes badge-wearers for alerting.)
Roles
| Role | Who it's for |
|---|---|
| Administrator | Manages Staff Safe setup and configuration — full access to everything. |
| User | Front-line coordinators who manage staff and badges and respond to alerts. |
| Alerts User | Responders who acknowledge, resolve, and document alerts. |
| Viewer | People who monitor alerts and dashboards without responding. |
| Mobile User | Responders who use the Kio Staff Safe Alerts mobile app. Grants sign-in and view access only — pair it with Administrator, User, or Alerts User to acknowledge and resolve alerts. |
For exactly what each role can do, see the matrix below.
What each role can do in the Staff Safe web app
Yes means the role has the permission; No means it does not.
| Permission | Administrator | User | Alerts User | Viewer |
|---|---|---|---|---|
| View alerts in List and Simple View | Yes | Yes | Yes | Yes |
| Acknowledge and resolve alerts | Yes | Yes | Yes | No |
| View Dashboards | Yes | Yes | No | Yes |
| View the Staff Map View | Yes | Yes | No | No |
| Manage Staff and assign badges | Yes | Yes | No | No |
| Import and export staff with a CSV file | Yes | No | No | No |
| Manage Staff Roles | Yes | No | No | No |
| Manage Staff Groups | Yes | No | No | No |
| Manage Alert Rules | Yes | No | No | No |
Viewer is read-only. The Mobile User role gives no access to the Staff Safe web app.
Administrator and User both manage staff, but from different menus. Administrators work from Settings > Staff. The User role works from Staff > List, where the Staff ID can't be changed and CSV import and export are unavailable.
Access to the Kio Staff Safe Alerts mobile app
Mobile access works differently: a responder needs two roles, one for access and one for action.
- The Mobile User role grants sign-in and permission to view active alerts.
- One of Administrator, User, or Alerts User grants permission to acknowledge and resolve alerts.
Assigned Mobile User alone, a responder can sign in and view active alerts but cannot acknowledge or resolve them. The Viewer role does not apply to the mobile app.
For more information, see About user access to Kio Staff Safe Alerts mobile app.
Roles that live outside Staff Safe
Some Staff Safe setup and staff management are performed from other Kio Apps and require assigned roles within these apps.
- Company Settings Administrator: For advanced Staff and Room management: deleting Staff Roles (Entity Types), editing Staff details (Entities), and managing Room Types and Room Matching.
- Entity Manager roles: For managing staff without needing access to Staff Safe: Staff Manager (view, add, and edit staff, including assigning badges) and Mobile User (assign Smart Badges to staff from the Kio Entity Manager mobile app).
- User Management Administrator: For directly creating users and assigning Staff Safe roles and campus access in the Users app, and viewing user profiles synchronized from your SSO identity provider.