Users and Roles

Open Team > Users as an Admin. Kaya has Viewer, Editor and Admin roles and no active Groups feature.

Admins can create users, edit names and email, assign a role, select local or OIDC authentication type, activate or deactivate an account, set a local password, designate a break-glass Admin and reset another user's TOTP configuration. Local passwords require at least 12 characters. Email addresses identify accounts and must remain unique.

Deactivating a user prevents future authentication. Review active sessions and linked OIDC identities when changing authentication type. TOTP reset removes the configured second factor; confirm the user's identity through an independent channel first.

The /setup route creates only the first Admin when no user exists. There is no public self-registration workflow.

Related: Permissions, Authentication.