Kinabase Logo
Help & Support

Assign Roles & Permissions

Managing user access


As your Kinabase workspace grows, it's worth deciding who should see or edit which parts of your data. Role

s and Permission s control that, so users only have the access they need.

Why use roles & permissions?

Data security

Only the right people can edit or view certain collections, fields and records.

Efficiency

Team members spend less time navigating irrelevant data, and more time on what matters for their job.

Compliance

Meeting data protection standards, such as ISO 9001 or GDPR, is easier when access is tailored deliberately.


1. Roles

A role groups users with similar access needs - for example, 'Sales', 'Engineering' or 'Manager'. Roles don't override a user's type: they define day-to-day permissions, not system-level access such as System admin or Billing admin. See Understand User Types for that distinction.

Kinabase groups roles into:

  • System Roles - built-in roles, including Everyone, which applies to every user and can't be deleted or renamed.
  • Your Roles - the custom roles your organisation creates.

You can assign a user more than one role - useful for people who work across teams.

1. Add a role

Go to Settings → Organisation → Roles, click Add Role, give it a name and description, and optionally assign existing users.

2. Manage an existing role

Use the options menu (⋯) next to a role to rename it, add or remove users, or duplicate or delete it.



2. Permission levels

Permissions define what each role can do. For example, your 'Sales' role might have View & Edit on 'Leads' and 'Clients', but No Access to 'Financial Records'.

Kinabase has four permission levels: No Access, View Only, View & Edit, and Not Enabled (for features that are switched off for that role entirely).

Permissions are set per column:

ColumnWhat it controls
RecordsViewing and editing records.
ActivitiesLogging and viewing activities.
TasksCreating and viewing tasks.
FilesUploading and viewing files.
ConfigureChanging the collection's setup - independent of whether the role can view records.
ImportBringing data into the collection.
ExportDownloading data out of the collection.
Bulk DeleteDeleting multiple records at once.
EmailSending emails from records.

1. Open the role

Under Settings → Organisation → Roles, select the ⋯ menu next to the role, then select Edit Permissions.

2. Set access levels

For each collection, set the level for each column that applies.

3. Save

Click Save Changes to confirm.


Fine-tuning at the collection level

For more granularity - right down to individual fields, or different rules per workflow stage - open a collection's Configure panel via the ⋯ menu in its toolbar or sidebar entry, then go to Permissions.



3. Balancing Everyone against specific roles

Kinabase includes an Everyone role by default, applied to every user in your organisation. We recommend keeping this minimal - View Only or No Access - and granting more specific access through roles like 'Engineering' or 'Sales'. This keeps a secure baseline while avoiding accidental overexposure of sensitive data.

An individual role's permissions can never be set lower than what Everyone already grants - to restrict access for a specific role, lower the Everyone baseline first.


4. Checking what a colleague can see

When a Colleague

cannot see a record or view that you can, looking at Kinabase as a System admin will not show you their permissions. View as user opens a new tab with that person's access, records why you opened it, and leaves your own sign-in in place. Never share a password or sign in as someone else to check.

View as user is only available for an Active colleague who is not a System admin, and you cannot use it on your own account.

1. Open View as user

Go to Settings → Organisation → Users, select the ⋯ menu on the colleague's row, then Admin actions, then View as user.

2. Enter a reason

The dialog title is View Kinabase as followed by their name. Type a Reason - the Open button stays disabled until you do.

3. Work in the new tab

Click Open. Kinabase starts the session in a new tab with that colleague's permissions and views, including which records they can open. Your original tab stays signed in as you. If your browser blocks the tab, use Open it now on the warning that appears.

A banner at the bottom reads Viewing as that person, with a countdown and an Exit button. Hover it to see the reason you entered.

4. Exit when you are done

Click Exit to end the session and close the tab. Your own sign-in is not affected. The tab expires on its own after 4 hours.

What you cannot do while viewing as someone

Password, multi-factor authentication, email, and sign-in method changes are blocked while you act as someone else. You also cannot change that person's name, profile photo, or notification settings from the tab.

If you view as a Portal-only user, the tab may open on Choose a portal to continue. The banner and Exit button still appear there.

Everything you do in the tab is attributed to you, acting as that colleague. Activity

entries, tasks, and record details show your name followed by (acting as) the colleague, and the Event Log records View As Started with your reason and View As Ended when the session ends. Confirm the permission you saw before you change a role.

This is separate from Preview as user on a portal, which shows an external portal user's view without opening a session. See Portal views.


Need more help? Ask your System admin, or contact our support team via Help & Support.