The Kio platform uses role-based access control (RBAC) that is managed in the Users app. Roles control which apps a user has access to and what they can do within each app.
This overview covers the roles defined in the Users app itself, then points to each of the Kio App's own roles. Per-app roles — such as those for Kio Cloud Apps, Kio Apps, and Kio Mobile Apps — — are documented in each app's user-access reference, provided in the Per-app roles section below.
Roles in the Users app
The Users app has four assignable roles. These are the roles that appear in the role picker when you assign access to a user.
| Role | What it allows |
|---|---|
| Administrator | Full access to the Users app. Manage users, manage user groups, view all profiles, view the account's API key (the Security page), and read-only access to Smart Location. Often referred to in Kontakt.io documentation as the User Management Administrator. |
| User | Basic authenticated user. Profile access only. The default role for any active user profile. |
| API Integration | Required to see the Integration API menu and manage integration API clients used by third-party systems. Does not include managing human users. |
| SPM Manager | This role is required to be enabled by Kontakt.io. The role is used to manage SPM role assignments. Used by clinical apps to control access to sensitive patient data. Assigning SPM role assignments also requires the Administrator role — on its own, SPM Manager cannot assign roles or view user profiles. |
Administrator role
The Administrator role is the broadest role in the Users app. It grants user management, user-group management, profile access, access to the account's API key on the Security page, and read-only access to Smart Location. For most accounts, this is the role to assign to the people responsible for managing user access or viewing SSO user profiles and groups.
The role is labeled Administrator in the Users app. Kontakt.io documentation uses the longer phrase User Management Administrator to distinguish from the Administrator roles defined in other apps.
Managing API Integration clients
Integration API clients are non-user accounts that represent third-party systems integrating with Kio Cloud. They have their own role assignments, separate from the Kio Apps roles.
To manage integration API clients, a user must be assigned both the Administrator and API Integration role. The API Integration role makes the Integration API menu available, where users can create, edit, and delete integration clients.
SPM roles
SPM roles are a separate category of roles for clinical apps that have Protected Health Information (PHI) and Sensitive Personally Identifiable Information (PII). Only users with the SPM Manager role, combined with the Administrator role, can view or change the SPM role.
The SPM Access tab appears on a user profile only when they are assigned the SPM Manager role. This tab displays the SPM roles available in your organization's Kio account and the roles currently assigned to the selected user. The available SPM role names depend on the applications deployed in your organization.
Per-app roles
Each Kio platform app has its own roles. Users must be assigned a role within an app before the app appears on their Kontakt.io Launchpad. The same role-based access control also applies to Kio Mobile Apps.
Kio Cloud Apps
- About user access to Company Settings
- About user access to Device Health
- About user access to Device Management
- About user access to Entity Manager
- About user access to Policy Foundry
- About user access to Smart Location
Kio Apps
- About user access to Asset Tracker
- About user access to Staff Safe
- About user access to Temperature Monitoring
Kio Mobile Apps
- About user access to Kio Entity Manager
- About user access to Kio Setup Manager
- About user access to Kio Staff Safe Alerts
API keys
The Kio Cloud account has a single API key for access to Kontakt.io APIs and SDKs. It is a per-account (company) key — there are no per-user API keys. Only a User Management Administrator can view it, on the Security page in the Users app (Users > Security).
The API key authenticates API and SDK requests for the account; it is a credential, not a role. Keep it confidential — treat it as your organization's key for integration and SDK access.