Contents
User Management
Create operator accounts and control access to Kalytera with fine-grained permissions.
Overview
Kalytera has a granular permission system that lets you control exactly which parts of the system each user can access. Access is managed at two levels: module-level permissions (coarse — e.g., can this user access the Alarms module?) and entity-level permissions (fine — e.g., can this user view camera "Server Room"?).
Navigate to Setup → Users (or Admin → Permissions) to manage users.

Creating a User
- Click Add User.
- Enter the username and password (or email address for SSO tenants).
- Assign a Permission Template to pre-fill a sensible set of permissions (see below), or set permissions manually.
- Click Create User.
The new user can immediately log in with the provided credentials. Passwords must meet the configured complexity requirements (minimum 8 characters, at least one digit and one lowercase letter by default).
Permission Templates
Permission templates provide a one-click starting point for common user roles:
| Template | Description |
|---|---|
| Administrator | Full access to all modules, devices, and system configuration. |
| Operator | Access to live view, playback, alarms, and maps. Cannot change system settings. |
| Viewer | Read-only access to live view and playback only. |
| Device Manager | Can add, edit, and remove devices and change recording settings. |
| Technician | Can access Health Monitoring and diagnostics. Cannot access live video or recordings. |
| Auditor | Read-only access to alarms, events, and audit logs. Cannot view live video. |
After applying a template, you can adjust individual permissions to fine-tune access for a specific user.
Module-Level Permissions
Module permissions control access to entire sections of Kalytera. Each module has View and Edit rights (where applicable):
| Module | View | Edit |
|---|---|---|
| Live View | Watch camera streams in real time | Manage grid layouts and saved views |
| Playback | Browse and play recorded footage | Export clips to MP4 |
| Alarms | See active alarms | Acknowledge, resolve, and configure rules |
| Devices | View device list and status | Add, edit, and remove devices |
| Recording | View recording configuration | Change recording modes and schedules |
| Maps | View floor plan maps | Edit maps and camera positions |
| Health Monitoring | View device health reports | Manage health check thresholds |
| Users & Permissions | View user list | Create, edit, and deactivate users |
| System Settings | View system configuration | Modify system settings |
Entity-Level Permissions (Camera Restrictions)
In addition to module permissions, you can restrict a user to only certain cameras. This is useful when you have multiple sites or tenants and need to ensure an operator can only see their own cameras:
- Edit a user and scroll to the Device Access section.
- Switch from All Devices to Selected Devices.
- Check the cameras this user should be allowed to access.
- Click Save.
When device restrictions are in effect, the camera does not appear in the user's device tree, live view options, playback search, or alarm assignments — as if it doesn't exist for that user.
Deactivating and Deleting Users
- Deactivate: Prevents the user from logging in without deleting their account or activity history. Useful for temporary suspension (employee on leave, etc.).
- Delete: Permanently removes the account. Activity logs and alarm acknowledgements previously made by this user are retained for audit purposes.
The built-in admin account cannot be deactivated or deleted. To change the admin password, navigate to Admin → Security or use the user profile page while logged in as admin.
Audit Logging
All significant user actions are recorded in the system audit log: logins, permission changes, camera additions/removals, recording configuration changes, and alarm acknowledgements. Access the audit log from Admin → Audit Log.