The Kio platform uses Role-Based Access Control (RBAC). Roles control which apps a user can access and what they can do within each app.
User Management roles
The User Management roles control who can view, add, edit, and manage users.
To manage users or assign app roles, a user must be assigned the Administrator role in User Management. In Kontakt.io documentation, this role may also be referred to as the User Management Administrator role to distinguish it from Administrator roles in other Kio apps.
| Role | What it allows |
|---|---|
| Administrator | Provides full access to the Users app. Users with this role can manage users and user groups, view user profiles, assign app roles, view the account API key on the Security page, and access Smart Location in a read-only mode. |
| User | Provides basic authenticated access. Managed users, who sign in with a username and password instead of SSO, can also change their password. This is the default role for active user profiles. |
| API Integration | Provides access to the Integration API menu, where authorized users can manage integration API clients used by third-party systems. To manage integration API clients, a user must also have the Administrator role. |
| SPM Manager | Allows authorized users to manage Secure Patient Management (SPM) role assignments for the Kio apps that include protected health information (PHI) or personally identifiable information (PII). To view or change SPM Access role assignments, a user must also have the Administrator role. On its own, the SPM Manager role does not allow a user to assign roles or view user profiles. The SPM Manager role is required to be enabled by Kontakt.io. |
Administrator role
Assign the Administrator role to people who are responsible for managing user access, assigning app roles, or viewing SSO user profiles and groups.
The role is labeled Administrator in User Management. Kontakt.io documentation may use the longer phrase User Management Administrator when needed to distinguish this role from Administrator roles in other apps.
API Integration role
Integration API clients are non-user accounts that represent third-party systems integrating with Kio Cloud. These clients have their own role assignments, separate from Kio app roles assigned to users.
To manage integration API clients, a user must be assigned both the Administrator and API Integration roles. The API Integration role gives users access to the Integration API menu, and the Administrator roles gives the access to create, edit, and delete integration API clients.
SPM roles
Secure Patient Management (SPM) roles are a separate category of roles for the Kio apps that have Protected Health Information (PHI) and Sensitive Personally Identifiable Information (PII). Only users with the SPM Manager role, combined with the Administrator role, can view or change the SPM role assigned to users.
The SPM Access tab appears on a user profile only when they are assigned to a SPM role. This tab displays the SPM roles available in your organization's Kio account and the roles currently assigned to the selected user. The available SPM roles depend on the Kio apps and EHR integrations activated in your organization's account.
Kio apps roles
Each Kio app has its own roles. Users must be assigned a role within an app before the app appears on their Kontakt.io Launchpad.
Kio Cloud Apps
- About user access to Company Settings
- About user access to Device Health
- About user access to Device Management
- About user access to Entity Manager
- About user access to Policy Foundry
- About user access to Smart Location
Kio Apps
- About user access to Asset Tracker
- About user access to Staff Safe
- About user access to Temperature Monitoring
Kio Mobile Apps