Access to Kio Temperature Monitoring is managed in the Users app in the Kio Cloud section on the Launchpad, not within Temperature Monitoring itself. Each person who needs access must have a user profile and be assigned a Temperature Monitoring role. For users whose access is required to be limited to a specific department, a home location must also be assigned.
User profiles are created and managed by users assigned to the Kio User Management Administrator role. For organizations without SSO integration, Temperature Monitoring Administrators and System Managers are typically also assigned the Kio User Management Administrator role to manage users directly. For accounts that have SSO integration, user profiles and role assignments are managed through the identity provider and can be viewed only within Kio Cloud User Management.
This article covers the Temperature Monitoring roles and how access works. For step-by-step user management tasks, see the Users app articles.
Temperature Monitoring roles
Temperature Monitoring has five roles.
| Role | Scope | What it is for |
|---|---|---|
| Administrator | Campus-wide | Manage Storage Units, Threshold Settings, and Alert Rules; view and generate reports; respond to alerts. No access to Advanced preferences. Typically compliance managers, pharmacy directors, and system owners. |
| System Manager | Campus-wide | Everything the Administrator can do, plus full access to Advanced preferences (the only role that can view or edit them). |
| Facilities Manager | Campus-level | View and respond to alerts, install Monitors, and view and generate reports. Cannot create Storage Units, Threshold Settings, or Alert Rules. |
| User | Department-level | View and respond to alerts and measurement history for the assigned department, and view and generate reports. No configuration access. |
| Monitoring User | Department-level | View and respond to alerts and measurement history for the assigned department. No access to reports, the Devices section, or configuration. |
What each role can do
Yes means the role has access to the area; No means it does not. Department means the role is limited to its assigned department.
| Capability | Administrator | System Manager | Facilities Manager | Monitoring User | User |
|---|---|---|---|---|---|
| View Storage Units, Rooms | Yes | Yes | Yes | Department | Department |
| View and respond to alerts | Yes | Yes | Yes | Department | Department |
| View and generate reports | Yes | Yes | Yes | No | Yes |
| View the Devices | Yes | Yes | Yes | No | Yes |
| Install Monitors in Kio Setup Manager | Yes | Yes | Yes | No | No |
| Create and manage Storage Units, Threshold Settings, Alert Rules | Yes | Yes | No | No | No |
| Access Advanced preferences (view or edit) | No | Yes | No | No | No |
The two distinctions to get right when assigning roles: only the System Manager can access Advanced preferences, and the User role gets reports while the Monitoring User does not.
How location access is managed
The campuses and departments a user has access to are also set in the Kio Cloud Users app:
- Campus access applies to the system-wide roles (Administrator, System Manager, Facilities Manager). They have access to all campuses by default, and you can restrict a person to specific campuses.
- Assigned Home Location applies to the department-level roles (Monitoring User and User). It sets the campus and department they have access to, so they see only their own department's Storage Units and Rooms. A department-level role without a Home Location has no Storage Units or Rooms to work with.
You set both when you assign a person's role. See Assign roles and access to a user.
Groups
Instead of setting roles and campus access individually within each user's profile, you can assign them to a Group and add members to it. Members inherit the Group's application roles and campus access in addition to anything assigned directly on their profile. Use Groups to manage access for a team in one place. See About Groups, Assign application roles to a Group, and Assign campuses to a Group.
Managed and SSO users
How users are created and maintained depends on whether your organization uses single sign-on (SSO):
- Managed users are created and maintained directly in the Users app.
- SSO users sign in through your identity provider, which supplies their identity and roles. You still set an SSO user's Assigned Home Location in the Users app.
Manage users
The tasks for managing users are shared across all Kio apps and managed in the Users app:
- Add a user — create a managed user.
- Assign roles and access to a user — give a person a Temperature Monitoring role, plus campus access or an Assigned Home Location.
- Enable, disable, or delete a user — change or remove a person's access.
Assigning Temperature Monitoring roles and Home Locations requires the User Management Administrator role.
Installing Monitors needs an extra role
Installing Monitors requires a Temperature Monitoring role with install access (Administrator, System Manager, or Facilities Manager) plus the platform-specific Kio Setup Manager role:
| Platform | Role required |
|---|---|
| iOS | Device Management Temp Monitor Installer |
| Android | Setup Manager (mobile) Temp Monitor Installer |