Skip to main content

User Roles

Understand the different user roles in Kuviq.

Overview

Kuviq uses roles to define what users can access and do. Each role has a specific purpose and set of permissions.

Available Roles

RolePurpose
Super AdminComplete system control including billing
AdminFull operational access without billing
ManagerOperational management and oversight
UserDay-to-day inspection and basic access

Super Admin

Purpose

The Super Admin has complete control over the organization, including sensitive operations like billing and data management.

Capabilities

AreaCan Do
UsersCreate, edit, delete all users including admins
ItemsFull control over all items
InspectionsFull control over all inspections
ConfigurationAll settings and templates
BillingManage subscription, payments, invoices
DataExport, delete, archive organization data
SecurityAudit logs, security settings

Who Should Have This Role

  • Organization owner
  • IT administrator
  • Financial controller
  • 1-2 people maximum recommended

Limitations

  • Cannot be demoted by regular Admins
  • Must have at least one Super Admin
  • Self-demotion requires another Super Admin

Admin

Purpose

Admins manage day-to-day operations and user administration without access to billing.

Capabilities

AreaCan Do
UsersCreate, edit, delete users (not Super Admins)
ItemsFull control over all items
InspectionsFull control over all inspections
ConfigurationModify all settings and templates
ReportsGenerate all reports
LocationsManage all locations

What Admins Cannot Do

  • Access billing and subscription
  • Manage Super Admin accounts
  • Delete organization
  • View financial data

Who Should Have This Role

  • Department managers
  • Safety managers
  • Operations managers
  • Team leads with admin responsibilities

Manager

Purpose

Managers oversee operations without making configuration changes.

Capabilities

AreaCan Do
UsersView users in their scope
ItemsCreate, edit, view all items
InspectionsCreate, edit, view all inspections
ReportsGenerate operational reports
LocationsView all locations

What Managers Cannot Do

  • Create or edit users
  • Modify configuration (templates, item types)
  • Delete items or inspections
  • Change organization settings

Who Should Have This Role

  • Shift supervisors
  • Site managers
  • Department leads
  • Quality managers

User

Purpose

Users perform day-to-day inspection tasks and basic operations.

Capabilities

AreaCan Do
ItemsView assigned/accessible items
InspectionsPerform inspections, view own history
QR CodesScan QR codes
ProfileEdit own profile

What Users Cannot Do

  • Manage other users
  • Delete items
  • Configure system
  • Access admin features
  • Generate advanced reports

Who Should Have This Role

  • Inspectors
  • Technicians
  • Field workers
  • General staff

Role Comparison Matrix

Item Permissions

ActionSuper AdminAdminManagerUser
View all itemsLimited
Create items
Edit itemsOwn
Delete items--
Export items-

Inspection Permissions

ActionSuper AdminAdminManagerUser
View allOwn
Perform
EditOwn
Delete--
Export-

User Management

ActionSuper AdminAdminManagerUser
Invite users--
Edit users-Own
Delete users--
Change rolesLimited--

Configuration

ActionSuper AdminAdminManagerUser
Item typesViewView
TemplatesViewView
LocationsViewView
Settings--

Billing

ActionSuper AdminAdminManagerUser
View billing---
Change plan---
View invoices---
Update payment---

Assigning Roles

During Invitation

  1. Go to Admin > Users
  2. Click Invite User
  3. Enter email
  4. Select role
  5. Send invitation

Changing an Existing User's Role

  1. Go to Admin > Users
  2. Click on the user
  3. Click Edit
  4. Change the role
  5. Save

Restrictions

  • Cannot change your own role
  • Admins cannot create Super Admins
  • Admins cannot demote Super Admins
  • Must have at least one Super Admin

Role Recommendations

Small Teams (2-10 people)

Team SizeRecommended Roles
2-31 Super Admin, rest Users
4-61 Super Admin, 1 Admin, rest Users
7-101 Super Admin, 1-2 Admins, 1-2 Managers, rest Users

Medium Teams (10-50 people)

PeopleRecommended
1-2Super Admin
2-5Admin
5-10Manager
RestUser

Large Organizations (50+)

RoleNumber
Super Admin1-2
AdminPer department
ManagerPer team/location
UserAll others

Common Scenarios

Single Person Organization

  • Assign yourself Super Admin
  • Full control as the only user

Small Business

RoleWho
Super AdminOwner
UserStaff

Multi-Site Operation

RoleWho
Super AdminCorporate admin
AdminRegional managers
ManagerSite supervisors
UserInspectors

Compliance-Focused

RoleWho
Super AdminCompliance officer
AdminQuality managers
ManagerTeam leads
UserInspectors

Best Practices

Principle of Least Privilege

Give users only the access they need:

  1. Start with User role
  2. Upgrade only if needed
  3. Document why higher access is needed

Regular Reviews

Periodically review role assignments:

  • Who has Admin/Super Admin?
  • Are roles still appropriate?
  • Any role changes needed?

Avoid These Mistakes

  1. Too many Super Admins - Increases risk
  2. Everyone as Admin - Defeats purpose of roles
  3. Not using Manager - Missing middle tier
  4. Not documenting - Forget why someone has access

Troubleshooting

User Can't Access Feature

  1. Check their role
  2. Review role permissions
  3. Consider if they need a higher role
  4. Or use location-based access instead

Wrong Role Assigned

  1. Edit the user
  2. Change their role
  3. Have them refresh browser

Can't Demote Super Admin

  • Another Super Admin must do it
  • Ensure at least one Super Admin remains

Next Steps