User Management
Create operator accounts and control access to Kalytera with fine-grained permissions.
Overview
Kalytera has a granular permission system that lets you control exactly which parts of the system each user can access. Access is managed at two levels: module-level permissions (coarse — e.g., can this user access the Alarms module?) and entity-level permissions (fine — e.g., can this user view camera "Server Room"?).
Navigate to Configure → User Management to manage users and permissions.
Creating a User
- Click Add User.
- Enter the local username and password.
- Assign a Permission Template to pre-fill a sensible set of permissions (see below), or set permissions manually.
- Click Create User.
The new user can immediately log in with the provided credentials. Passwords must meet the configured complexity requirements (minimum 8 characters, at least one digit and one lowercase letter by default).
Permission Templates
Permission templates provide a one-click starting point for common user roles:
| Template | Description |
|---|---|
| Administrator | Full system access with all permissions. |
| Device Manager | Manage devices, health, and maps. |
| VMS Operator | Operate video, alarms, and the intrusion panel. |
| Viewer | Read-only access to all features. |
| Technician | Configure devices, analytics, and intrusion, and operate I/O. |
| Auditor | Read-only access with export and search permissions. |
After applying a template, you can adjust individual permissions to fine-tune access for a specific user.
Module-Level Permissions
Module permissions control access to entire sections of Kalytera. Each module has View and Edit rights (where applicable):
| Module | View | Edit |
|---|---|---|
| Live View | Watch camera streams in real time | Manage grid layouts and saved views |
| Playback | Browse and play recorded footage | Export clips to MP4 |
| Alarms | See active alarms | Acknowledge, resolve, and configure rules |
| Devices | View device list and status | Add, edit, and remove devices |
| Recording | View recording configuration | Change recording modes and schedules |
| Maps | View floor plan maps | Edit maps and camera positions |
| Health Monitoring | View device health reports | Manage health check thresholds |
| Users & Permissions | View user list | Create, edit, and deactivate users |
| System Settings | View system configuration | Modify system settings |
Entity-Level Permissions (Camera Restrictions)
In addition to module permissions, you can restrict a user to only certain cameras. This is useful when you have multiple sites or tenants and need to ensure an operator can only see their own cameras:
- Edit a user and scroll to the Device Access section.
- Switch from All Devices to Selected Devices.
- Check the cameras this user should be allowed to access.
- Click Save.
When device restrictions are in effect, the camera does not appear in the user's device tree, live view options, playback search, or alarm assignments — as if it doesn't exist for that user.
Account status and credentials
Use the active/inactive control to prevent an account from signing in while retaining its record. Password changes are handled through the account and profile workflows exposed by the application.
Always keep at least one active account with administrative permissions. Verify another administrator can sign in before deactivating an administrative account.
Audit Logging
All significant user actions are recorded in the system audit log: logins, permission changes, camera additions/removals, recording configuration changes, and alarm acknowledgements. Access the audit log from Admin → Audit Log.