Access Manager Overview

  • Updated

The Access Manager is where Company Administrators manage user access, roles, and compliance for employees at their locations. From here, you can add users, assign roles, monitor compliance, and off-board staff who leave.

Please Note: You need Access Manager permissions enabled in your profile to open and manage user accounts.

What You Can Do in Access Manager

Access Manager supports the full user lifecycle. Common tasks include:

  • Onboarding new employees and assign their roles.
  • Monitoring user compliance status.
  • Off-boarding departing employees.
  • Tracking user activity and compliance.

Key features include a searchable user list, role assignment and stacking, compliance monitoring, and activity tracking.

What You Control vs. What Kipu Controls

You manage day-to-day user settings. Kipu manages the underlying content and configuration.

You control:

  • User accounts
  • Role assignments
  • Permissions
  • Notifications

Kipu controls:

  • Training content
  • Forms and surveys
  • Regulatory data
  • Location settings

Access Manager Layout

Use the paths below to reach each part of user management.

  1. Access Manager — Client Side sidebar > Access Manager

  2. User List — Access Manager > Users tab

  3. User Details — Users list > Show or Edit on a user
  4. User Compliance Report — Sidebar > User Compliance Report, or User Profile from Access Manager

  5. Users Compliance Summary — Sidebar > Location Compliance Report > Users Compliance Summary section

Note: You can also reach a company-wide user list from the location dropdown by selecting Company Admin > Users. For day-to-day location management, use Access Manager on the Client Side.

Understanding the User List

The user list within the Access Manager shows key details for every user at your location. Each column tells you something specific:

  • ID — The user's system ID.
  • First Name / Last Name — The user's name.
  • Username — The login username. Click it to open user details.
  • Roles — Roles assigned for this company.
  • Department — The user's department.
  • Title — The user's job title.
  • Date of Hire — The user's start date.
  • isActive — Whether the user is fully enabled. See User Status below.

Email and last login do not appear in the list. You will find them on the individual user detail page.

Filtering and Searching

To find a specific user quickly, use these tools:

  1. Filter the list by All Users, Enabled Users, or Disabled Users using the dropdown.
    • Click Filter to apply your selection.
  1. Use the per-column search boxes to narrow results. You can also click on any column heading to sort the list.

Add a New User

To create a new user account:

  1. Click Add New User in the top-right corner.
  2. Complete the user information form, including name, username, roles, department, and date of hire.
  3. Once all details have been entered, save the new user.

Manage Existing Users

You can view and edit any user directly from the list.

  1. Click Show next to the user you want to manage/review.
  2. When the user profile opens, click Edit in the top-right corner to make changes.
  3. Save your changes when finished by clicking on the Update button at the bottom of the page.

Understanding User Roles

Roles shape a user's entire experience in the system. Each role controls three things:

  • Content assignment — Which trainings and documents the user receives.
  • System access — Which features within Kipu Compliance the user can open.
  • Permissions — Which actions the user can perform.

Role Stacking

A user can hold more than one role at a time. When roles stack, they combine:

  • Combined requirements — Each role adds its own content.
  • Unified view — The user sees all assignments together.
  • Aggregate compliance — The compliance score reflects all roles.


Example: A nurse with both a Clinical role and an HR role receives the trainings from both, and their compliance score reflects all of them.

User Permission Flags

When you add or edit a user, the form includes permission checkboxes. These control what a user can access beyond their assigned roles. They are the most powerful settings you can grant.
 

Important: The Admin permission flag is different from having a role named "Admin" or "Admin/Super User." The flag is a separate checkbox on the user form. Roles and permission flags work together but control different things.

Where to find them: Access Manager > select a user > Edit. The checkboxes appear in the company role section of the form.

Here is a quick summary of the three flags:

  • Admin (form label: Is Admin? No Restrictions) — Full access to all content at the location, bypassing role-based restrictions.
  • Access Manager (form label: Has Access Manager?) — The ability to manage users at the location.
  • Manage Training Center (form label: Manager of Training Center) — The ability to review any employee's training and quiz progress at the location.

Admin (Is Admin? No Restrictions)

The Admin flag gives a user unrestricted access to content at their location. The system treats this as "no restrictions" on role-based permissions.

Admin users can:

  • Forms — View, create, edit, and delete all form submissions, regardless of role.
  • HR Documents — Access all HR documents at the location.
  • Employee Surveys (Competencies) — Access all competencies at the location.
  • Cross-user visibility — View other users' submissions across the location.
  • Compliance reports — View other users' User Compliance Reports.
  • Training Center — Review training and quiz progress for all users.
  • Impersonation — Log in as other users for troubleshooting.
  • Access Manager and Manage Training Center — Included automatically.

When to use Admin:

  • Facility directors or compliance leads who need to see everything at a location.
  • Users who troubleshoot issues across all content types and staff.
  • Situations where role-based permissions are too restrictive.

Caution: Admin bypasses role-based content restrictions entirely. Assign it only to users who truly need unrestricted access. The wrong permission level can expose restricted information.

Access Manager (Has Access Manager?)

The Access Manager flag lets a user manage other users at their location through the Access Manager menu.

Access Manager users can:

  • View the user list for the location.
  • Add users and create new accounts.
  • Edit users, including details, roles, departments, and permission flags.
  • View user details, such as contact info, login history, and roles.
  • Run Mass Upload Validation to bulk-check user data before import.
  • Manage Training Permissions for a specific user from the edit page.
  • Assign departments (when combined with HR, Admin/Super User, or Company Admin access).
  • Use the API Access tab to view and manage API credentials.

This flag alone does not grant:

  • Reset password or impersonate — Requires Admin, HR, or Facility Director/Dev Ops role.
  • Unrestricted content access — Requires the Admin flag or role permissions.
  • Review of all users' training progress — Requires Manage Training Center, Admin, or HR.

Note: Users with the HR role can open Access Manager even without this checkbox. The Admin flag also grants Access Manager access automatically.

When to use Access Manager:

  • HR coordinators who onboard and off-board staff.
  • Location administrators who manage accounts but should not see all compliance content.
  • Team leads who update user details and role assignments.

Manage Training Center

The Manage Training Center flag (form label: Manager of Training Center) lets a user view and oversee training progress for all employees at the location, not just their own.

Manage Training Center users can:

  • Employee dropdown — Switch between employees to view any user's progress.
  • Employee Summary — View an aggregate summary of training and quiz activity.
  • Training Compliance Score — See required and optional completion percentages.
  • Latest Activity — Review recent training and quiz completions.
  • Force to Retake — Reset a completed training or quiz so the employee retakes it.
  • Assign Training to Role — Set which trainings go to which roles.

This flag alone does not grant:

  • Access Manager — Requires the Access Manager flag or HR role.
  • Unrestricted forms, HR, or competency access — Requires the Admin flag.
  • User Compliance Reports — Requires Admin or HR role.
  • Reset password or impersonate — Requires Admin, HR, or Facility Director/Dev Ops role.

Note: Users with the HR or Admin/Super User role can also review all training progress, even without this checkbox. The Admin flag includes all Manage Training Center abilities plus unrestricted content access.

When to use Manage Training Center:

  • Supervisors or department managers who monitor training completion.
  • Clinical or training coordinators who review progress and force retakes.
  • Users who need training oversight without full Admin or Access Manager rights.

Caution: This flag reveals every employee's training and quiz status at the location. Assign it only to users who need that oversight.

How These Settings Work Together

Use this guide to grant the right access for each need:

  • To add, edit, or disable users — Grant Access Manager (or the HR role).
  • To monitor staff training progress — Grant Manage Training Center (or the HR role).
  • To see and manage all content and all users — Grant Admin.
  • For minimal HR onboarding access only — Grant Access Manager without Admin.

Keep these relationships in mind:

  • Admin includes full content access, Access Manager, Manage Training Center, impersonation, and visibility into all compliance and training data.
  • Access Manager alone covers user management and per-user training overrides, but not Admin content access or training oversight for all users.
  • Manage Training Center alone covers reviewing any user's training, Force to Retake, and Assign Training to Role, but not Access Manager or unrestricted content.

User Status

A user's status controls whether they can log in.

  • Active — The user can log in and access the system.
  • Inactive — The user cannot log in.

A user is fully active only when all three of these are enabled:

  1. The user account.
  2. The user's company role.
  3. The user's access to the specific location.

Inactive users cannot access the system and do not appear in active compliance reports or the Users Compliance Summary. They do remain in historical records.

Common Tasks

Viewing Login History

  1. Click Show on the user to open their details.
  1. Review the Last Login field on the detail page.

Resetting a Password

Available to Company Administrators, HR, and Facility Director/Dev Ops roles.

  1. Find the user in Access Manager, and click Reset Password.
  1. The user will receive a reset link by email to create a new password.

Impersonating a User

Available to Company Administrators, HR, and Facility Director/Dev Ops roles. Impersonation lets you view a user's access without their login credentials.

  1. Find the user in Access Manager, and click Impersonate (if available).
  1. The system will immediately logs you in as that user's permissions allowing you to troubleshoot as needed.

Note: All actions during impersonation are logged. Use it only for legitimate troubleshooting. You cannot impersonate Kipu administrator accounts.

Best Practices

Onboarding New Users

Follow these steps when adding a new employee:

  1. Assign the appropriate roles.
  2. Verify location access.
  3. Set the date of hire correctly.
  4. Monitor initial compliance completion.

Off-boarding Users

Follow these steps when an employee leaves:

  1. Mark the user as inactive.
  2. Transfer pending items if needed.
  3. Document the change in notes.
  4. Confirm the user is removed from active reports.

Troubleshooting

Use these checks to resolve the most common issues.

Issue: A user cannot log in.

  1. Confirm the account, company role, and location access are all enabled.
  2. Verify the username is correct.
  3. Reset the password if needed.
  4. Check company and location access in Access Manager.

Issue: A user is missing from the list.

  1. Check your filter settings.
  2. Confirm the user is assigned to the location.
  3. Check the active/inactive filter.
  4. Contact your administrator if you still cannot find them.

Frequently Asked Questions

Can I create roles myself?

No. The Kipu Compliance team configures all roles. Contact Kipu to request a new role.

How do I add a new user?

See the Add a New User section above for step-by-step instructions.

What happens to compliance data when I deactivate a user?

Historical data is retained. The user is removed from active compliance reports.

Can users have access to multiple locations?

Yes. You can assign users to multiple locations, each with its own role assignments.

Was this article helpful?

1 out of 1 found this helpful

Comments

0 comments

Article is closed for comments.