Kalytera has a granular permission system that lets you control exactly which parts of the system each user can access. Access is managed at two levels: module-level permissions (coarse — e.g., can this user access the Alarms module?) and entity-level permissions (fine — e.g., can this user view camera "Server Room"?).
Navigate to Configure → User Management to manage users and permissions.
The new user can immediately log in with the provided credentials. Passwords must meet the configured complexity requirements (minimum 8 characters, at least one digit and one lowercase letter by default).
Permission templates provide a one-click starting point for common user roles:
| Template | Description |
|---|---|
| Administrator | Full system access with all permissions. |
| Device Manager | Manage devices, health, and maps. |
| VMS Operator | Operate video, alarms, and the intrusion panel. |
| Viewer | Read-only access to all features. |
| Technician | Configure devices, analytics, and intrusion, and operate I/O. |
| Auditor | Read-only access with export and search permissions. |
After applying a template, you can adjust individual permissions to fine-tune access for a specific user.
Module permissions control access to entire sections of Kalytera. Each module has View and Edit rights (where applicable):
| Module | View | Edit |
|---|---|---|
| Live View | Watch camera streams in real time | Manage grid layouts and saved views |
| Playback | Browse and play recorded footage | Export clips to MP4 |
| Alarms | See active alarms | Acknowledge, resolve, and configure rules |
| Devices | View device list and status | Add, edit, and remove devices |
| Recording | View recording configuration | Change recording modes and schedules |
| Maps | View floor plan maps | Edit maps and camera positions |
| Health Monitoring | View device health reports | Manage health check thresholds |
| Users & Permissions | View user list | Create, edit, and deactivate users |
| System Settings | View system configuration | Modify system settings |
In addition to module permissions, you can restrict a user to only certain cameras. This is useful when you have multiple sites or tenants and need to ensure an operator can only see their own cameras:
When device restrictions are in effect, the camera does not appear in the user's device tree, live view options, playback search, or alarm assignments — as if it doesn't exist for that user.
Use the active/inactive control to prevent an account from signing in while retaining its record. Password changes are handled through the account and profile workflows exposed by the application.
Always keep at least one active account with administrative permissions. Verify another administrator can sign in before deactivating an administrative account.
All significant user actions are recorded in the system audit log: logins, permission changes, camera additions/removals, recording configuration changes, and alarm acknowledgements. Access the audit log from Admin → Audit Log.