User rights and access control

User rights and access control

User rights decide what each person sees and can do in KAMI. Almost every "why can't they see this?" question comes back here.

Where: My Team › Settings › Approvals & Access › User Rights You need: the user rights permission

Two questions, not one

A right answers what someone can do. A separate setting answers whose data they can do it to. Both have to be right, and confusing them causes most access problems.

Someone can hold a right and still see nothing, because their scope is limited to themselves. Someone else can have broad scope and still be blocked, because they lack the right. When access looks wrong, work out which of the two is missing before changing anything.

What the rights cover

Rights are grouped by what they govern:

GroupGoverns
Access rightsWhose records this person can reach
ActionsWhat they can do to a record — create, deactivate, delete
Profile data rightsWhich fields they can see, including sensitive ones
DocumentsViewing, adding, deleting and auto-approving documents
Company policiesManaging policies
Bulk dataImport and export
SettingsConfiguring the company
SecuritySecurity-related controls
AI agentAccess to Mel

Rights worth understanding before you grant them

Some rights are wider than their name suggests.

  • Access all employees removes the scope limit entirely. It is the difference between

a manager seeing their team and seeing everybody. Grant it deliberately.

  • Delete employee is not the same as deactivating. Deactivation is the normal path for

someone leaving; deletion removes the record. Most people who need to offboard need deactivate, not delete — see Deactivating, terminating and rehiring employees.

  • Auto-approve documents skips the approval queue. Useful for a trusted HR team,

wrong for most managers, because it removes the review step entirely.

  • Banking and ID fields are a separate right from general profile data, because they

are the fields that matter most if the wrong person sees them.

Why a tab or menu is missing

KAMI hides what you cannot use rather than greying it out. A missing tab means a missing right, not a fault.

Two things follow that surprise people:

  • A tab appears if you can open at least one thing inside it. Two people can both see

Settings and find different contents.

  • A tab can appear and be nearly empty. Managers commonly see Reports and Settings

with a single item, because the rest needs admin-level rights. That is expected — see My Team for managers.

Working out an access problem

When someone reports they cannot see something:

  1. Check the right first. Do they have the specific permission for that feature?
  2. Then check scope. Can they reach that employee's record at all, or only their own?
  3. Then check the module. A right cannot grant access to a module your company does

not have enabled.

  1. Have them sign out and back in. Rights are read when a session loads, so a change

may not appear until they do.

Good practice

  • Start narrow. It is easier to add a right than to discover months later that half

the company could see salaries.

  • Grant to roles, not individuals. Rights set per person drift, and nobody remembers

why a particular user has an unusual permission.

  • Review after a reorganisation. People who change role keep whatever they were given

in the old one.

Related articles