Skip to content
Kanonik
Menu
Help
Browse Help
On this page

Roles and inviting your team

The four roles you can give someone, what each one can do, how inviting and removing people works, and what an extra person costs.

Every person in your workspace signs in with their own account and holds one role. Each decision is recorded against the account that made it, so give everyone who writes or approves their own account rather than sharing one.

Who can invite

Only a Tenant Admin can invite people, change who has access, and remove people. You do it in the dashboard: choose Settings in the left-hand menu, then People.

Your AI cannot add, remove or change a person. People are managed in the dashboard only, so a prompt in a chat can never add someone who then approves work.

The four roles

  • Tenant Admin. Full control. Manages people, the subscription, Slack and framework licences, and can also direct the AI and approve work. A workspace must always keep at least one Tenant Admin.
  • Reviewer. Approves the work your AI drafts and reads the whole record.
  • Author. Directs the AI to draft and submit compliance work.
  • Auditor. Read-only access to your record and the audit export, for a fixed engagement.

Reviewer and Author are labels on the same set of permissions today: both can direct the AI and both can approve. What keeps work honest is the approval rule, which compares people, not labels. The first decision on a request belongs to the person who asked their AI for the work (a Tenant Admin can accept on their behalf when they are away), and items that need a second person must be sealed by someone else. Deciding on an approval request, item by item explains which items those are.

The team page shows how your duties are spread, for example "Duties are separated: 1 Admin, 2 Reviewers, 1 Author, 0 Auditors". If you have Authors and no Reviewer, it warns you.

Auditor is the read-only role

There is one read-only role today, and it is Auditor. Kanonik has no separate read-only role for colleagues inside your company yet, so someone who should read your record without approving anything is invited as an Auditor.

An Auditor can:

  • read the whole sealed record and the audit log,
  • produce the audit export,
  • through their own AI, propose an audit session or an audit finding, which someone on your team then approves, and finalize an audit session,
  • run Foresight on a planned change.

An Auditor cannot draft or approve compliance records. They never see what is waiting for approval: Needs you and Standing are not in their menu, and unsealed drafts are left out of what they see.

Inviting an Auditor needs two extra things: an engagement end date and a reason, such as the audit and the engagement letter it falls under. Access ends at the end of that day (UTC), and is removed automatically on that date.

Inviting someone

  1. Enter their email address and choose a role. A display name is optional.
  2. For an Auditor, add the end date and the reason. For anyone else a reason is optional, and worth giving.
  3. Choose Send invite.

What happens next depends on the person:

  • New to Kanonik. We email them a secure link to set their password and join.
  • The email could not be sent. The page shows a one-time password, once. Share it with them securely; they set their own password on first sign-in.
  • Already has a Kanonik account. No email is sent. Ask them to sign in; your workspace then shows up in their workspace switcher. They may need to sign out and back in first.

Every invite is written to your permanent record. Inviting someone who is already in the workspace with a different role does not change their role.

What an extra person costs

Solo includes one user. Before an invite that adds to your bill is sent, the page shows the amount and asks you to confirm it; saying no leaves the form as it was and nothing is charged. When you confirm, the charge for the rest of the current billing period is added straight away.

You are billed for the people who currently have access, so removing someone stops their charge.

Removing someone

On the team page, choose Remove next to the person, give a reason, and confirm with Remove access. Their role in your workspace ends and the change is recorded on your record. Their Kanonik account is not deleted, only their access to your workspace. You cannot remove the last Tenant Admin: give someone else the admin role first.

View activity next to a person opens the audit log filtered to what they did.

More help

Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email [email protected] and a person who works on the product answers.