Access to Company Settings is managed in the Users app in the Kio Cloud section of the Launchpad, not within Company Settings itself. Each person who needs access must have a user profile and be assigned a Company Settings role. An app appears on a user's Kontakt.io Launchpad only if they are assigned a role for it.
Roles are assigned by a user with the User Management Administrator role. See Add a user and Assign roles and access to a user.
What makes up a user's access
Access to Company Settings is by role only. Company Settings holds platform-wide configuration shared across the Kio Apps, so its roles are not limited by campus or department — the role alone determines what a user can do.
Roles
Company Settings has two roles.
| Role | Who it's for |
|---|---|
| Administrator | People who manage the platform-wide shared configuration: Entity Management, Room Management, and Webhooks. |
| User | People who manage webhook integrations only, with no access to entities or rooms. |
We recommend assigning at least two users to the Company Settings Administrator role.
What each role can do
Yes means the role has the permission; No means it does not.
| Capability | Administrator | User |
|---|---|---|
| Create, edit, and delete Entity Types | Yes | No |
| Create, edit, and delete Entities | Yes | No |
| Assign Tags to entities | Yes | No |
| Configure entity type statuses, icons, and colors | Yes | No |
| Import and export entities | Yes | No |
| Create, edit, and delete room types | Yes | No |
| Set entity status rules and workplace rules | Yes | No |
| Match rooms to room types | Yes | No |
| Import and export room types and room matching | Yes | No |
| Create, view, edit, and delete webhooks and variables | Yes | Yes |
| View the webhook history log | Yes | Yes |
How users and Groups are managed
How users are created and maintained depends on whether your organization uses single sign-on (SSO):
- Managed users are created and maintained directly in the Users app. A Managed Group can assign roles to several users at once.
- SSO users sign in through your identity provider, which supplies their identity and roles. These sync into the Users app as view-only — you change them in the identity provider.
Instead of setting roles in each person's profile, you can assign them to a Group and add members to it. Members inherit the Group's application roles in addition to anything set directly on their profile. See About Groups and Assign application roles to a Group.
The tasks for managing users are shared across all Kio apps and live in the Users app:
- Add a user — create a managed user.
- Assign roles and access to a user — give a person a Company Settings role.
- Enable, disable, or delete a user — change or remove a person's access.
Roles that live outside Company Settings
- User Management Administrator — required to create users and assign Company Settings roles, in the Users app.
- Kio Apps Administrators — each Kio App also has its own Administrator role with limited entity and room management permissions. For example, they cannot delete entities or edit Entity IDs, and they have view-only access to Room Types and Room Matching.
The Company Settings Administrator is the power-user role, with full access to the shared entity and room configuration — assign it only to those responsible for that shared configuration across the Kio Apps.