User Roles and Permissions Guide

Kutano uses a role-based system to control what actions users can perform. There are two levels of roles:

  1. Workspace Roles - Control what you can do across the entire Kutano workspace
  2. Status Form Roles - Control what you can do within specific team status forms

Workspace Roles Explained

Workspace roles determine your system-wide permissions:

Role Description Key Capabilities
Owner The primary administrator of the workspace • Delete the workspace
• Transfer ownership
• Full administrative control
Admin Helps manage the workspace • Manage workspace members
• Configure workspace settings
• Access administrative functions
Member Standard user role for employees • Create status forms
• Join existing forms
• Submit status updates
Guest Limited role for external collaborators • Join forms they're invited to
• Cannot create forms
• Limited workspace access

Status Form Roles Explained

When you're added to a specific status form, you're assigned one of these roles:

Role Description Key Capabilities
Owner The manager or creator of the form • Delete the form
• Transfer ownership
• Full control over form settings
Administrator Designated form manager • Add/remove members
• Update form settings
• Edit any status update
Contributor Regular team member • Submit their own status updates
• View all team updates
• Comment on updates
Commenter Stakeholder or interested party • View all status updates
• Add comments
• Cannot submit updates
Viewer Read-only access • View all status updates
• Cannot comment or submit

Common Permission Questions

Who can see my status updates?

Only people directly added to your status form can see your updates. Even workspace Owners and Admins cannot see form data unless they've been specifically granted access to that form.

Who can submit status updates?

Each status form column is assigned to a specific user who is responsible for updating it. Typically:

  • You can only update your own status update
  • Form Owners and Administrators can update any status update (helpful when someone is on vacation)
  • Other roles (viewer or commenter) cannot edit status update information

How are permissions enforced?

Permissions are enforced at both the user interface level (hiding buttons/features) and at the API level (preventing unauthorized actions). This ensures that users can only perform actions appropriate to their assigned roles.

How do I remove someone's access completely?

To remove someone's access to a status form or workspace, you must:

  1. Remove them from the status form: This can be done by a form Owner or Administrator through the form member settings page.
  2. Delete their workspace user record: This can be done by a workspace Owner or Admin in the workspace settings.

Once removed, the user will no longer have access to the form or workspace. If you delete their user record, their status updates will remain visible to other members of the form, but their personally identifiable information (PII) will be removed (first, last, email). If that is not desired, you can simply deactivate the user instead.

What happens to someone's data if I remove them?

If you remove a user from a status form, their status updates will remain visible to other members of the form. However, they will no longer be able to submit new updates or access the form.