Users and roles
How logins are created in KaryaFlow, what the three roles can do, and how a Tenant Admin changes what each role may see.
There is no separate Users screen
Everyone who signs into KaryaFlow — office staff and technicians alike — is an employee. Adding an employee creates their login at the same time.
Open Employees in the sidebar. That is the whole list.
Each person has two halves, and you see both on their page:
- The Profile card is their work record: employee code, name, designation, department.
- The Account Access card is their login: whether they can sign in, their role, and their login email.
Create a login
See Add your team for the full walkthrough. In short: Employees → Add Employee, fill in the name, designation, email, password and role, then click Create Employee.
The Email and Password boxes are not marked as required on the form, but the save fails without them. There is no way to sign in without both.
The three roles
| Role | What it is for |
|---|---|
| Tenant Admin | Runs the workspace. Sees everything and can change every setting. |
| Manager | Supervisor access to the Dashboard. What they see is up to you. |
| Technician | A field worker who uses the Technician app. |
When you add someone you can pick Technician or Manager. Tenant Admin is not offered on the form.
To change somebody's role later, open their page and use the Role control on the Account Access card. Two rules apply:
- You cannot change your own role.
- An admin's role is managed by your provider, not by you.
Turn a login on or off
On the Account Access card:
- Deactivate stops them signing in. Their records stay. Their app shows Account disabled.
- Activate lets them back in.
- Reset Password sets a new password for them. Type it and tell them. There is no email invitation.
If your plan has a seat limit, deactivating someone frees their seat. The Add Employee button greys out once every seat is used, and tells you how many you have.
Decide what a role can do
Go to Settings → Roles & Permissions. Only a Tenant Admin can open it.
Decide what each role can see and change across your workspace.
The screen is a table. Each row is one thing a person can do, with a plain description underneath. The three columns are your three roles.
Pick the area on the left
The rail lists All modules, then each area — Jobs, Attendance, Payroll, Reports and so on. Or type in Search features.
Turn switches on and off
Flip individual rows, or use the switch on a group heading to turn a whole area on or off for that role at once.
Click Save changes
Nothing takes effect until you save. The bar above the table tells you how many changes are waiting.
Some cells cannot be switched:
- Tenant Admin is always on, with a padlock. That role is never limited.
- Locked or Not available means the feature cannot be given to that role at all.
- Module off means the whole area is switched off for your workspace. Ask your provider.
A row marked Sensitive in amber changes money or deletes records. Read it before you grant it.
Made a mess of the Manager column? The ⋯ menu beside Save changes has Reset Manager to safe defaults.
See who is in each role
The People tab beside Permissions lists everybody, grouped by role, with a head count. It is read-only. To move somebody between roles, open their page.
What the technician's role changes on their phone
The role decides more than the Dashboard. On the Technician app it decides:
- whether a New Job button appears on their jobs list,
- which work statuses they may move a job into. If they see No work statuses are available for your role, their role has no stage to move to.