User Management is where you control who can sign in to the Kontakt.io platform and what each person can do. It's managed in the Users app, in the Kio Cloud section of the Launchpad, and applies across the whole platform. Each person has one user profile, and the roles assigned to it determine which apps they see and what they can do in each.
An app appears on a person's Kontakt.io Launchpad only if they are assigned a role for that app.
What makes up a user's access
- User profile — one per person, holding their name, email, sign-in method, and a Unique Ext ID. Created in the Users app or provisioned from your identity provider.
- Roles — assigned in the Users app; each app defines its own roles, and a role controls what the person can do in that app.
- Groups — assign roles and access to several users at once. A Managed Group is maintained in Kio Cloud; an SSO Group syncs from your identity provider and is view-only. See About Groups.
- Campus access — the campuses a person can work in. It applies across every Kio Cloud app. System-wide roles use campus access to scope where they work.
- Home location — the campus and department for a department-level role, set per user. See Assign and manage a home location.
What you can do in User Management
From the Users app, a User Management Administrator controls who has access and what they can do:
- Add and manage users — add a user, assign roles and campus access, set a home location, reset a password, manage multi-factor authentication (MFA), and enable, disable, or delete a user. Disabling a user suspends their sign-in without removing the profile; deleting removes it while retaining their historical activity.
- Manage Groups — apply roles and campus access to many users at once: create a Group, add members, and assign roles and campuses.
- Manage integration API clients — create and manage the non-human accounts that let third-party systems integrate with Kio Cloud.
Who manages users
Users, roles, and access are managed by a user with the User Management Administrator role. How they are managed depends on single sign-on (SSO):
- Without SSO — administrators create and manage users, roles, and Managed Groups directly in the Users app.
- With SSO — user profiles, roles, campus access, and Groups come from your identity provider and are view-only in the Users app. The one exception is a user's home location, which is always set in the Users app, even for SSO users.
See SSO and managed users and Platform roles overview.
Roles
A user's access is defined by the roles assigned to them in the Users app. The Users app itself has two main roles:
- User Management Administrator — manages users, groups, and role assignments across the account.
- User — the basic authenticated role, assigned to every active user; profile access only.
Each Kio Cloud app and Kio App adds its own roles on top of these. For the complete list — the Users-app roles and every app's roles — see Platform roles overview.