Users: Registration, Deletion, and Permissions
In POK Proof of Knowledge, you manage your team from the Team Members section. Administrators can invite new users with an administrator, operator, or reader role, and can also remove members or grant the signer permission. This guide walks you through those tasks and explains what each role and permission allows.
Open the Team Members section
- In the top navigation bar, on the right side, click your organization's name.
- Click "Team Members".
Add a new member
If you have administrator permissions, the first thing you see on this screen is the option to add a new member.
- In the pop-up window, enter the new user's email address.
- Select the role for the new user: administrator, operator, or reader.
- Choose the language of the invitation.
- Click "Invite".
POK then sends an email to the new user. They can access your organization by clicking "Go to the organization".
What roles can I assign, and what does each one do?
Every member has one of three roles:
- Administrator: full access, including inviting or removing team members, issuing credentials, and managing integrations.
- Operator: can create and preload credentials, but cannot issue them directly or manage team members.
- Reader: read-only access, for members who only need to view credentials, designs, and reports.
What is the signer permission?
Independent of their role, any member can also be granted the signer permission. A signer can digitally sign the credentials that require a signature, or reject signature requests. To assign it, click the pencil icon next to a member in the list, check "Assign signer role", and confirm.
Remove a member
Above the member list you will see counters for Members, Administrators, Operators, and Signers, followed by the list of members with their details. If you have administrator permissions, you can also delete a member from this list.
When you click the delete icon, POK asks you to confirm the removal. Once you confirm, the user is removed immediately and, if they try to log in afterwards, they will no longer have access.
Permissions for each role
| Functionality | Administrator | Operator | Reader |
|---|---|---|---|
| Design credentials | Yes | Yes | View only |
| Issue credentials | Yes | No, they can only preload | No |
| Bulk sending or rejection | Yes, their own or preloaded | No, they can only reject the ones they created | No |
| Integrations | Yes: use available applications, add new ones, or delete them | No | View only |
| Members | Add or delete members | No | No |
The signer permission works on top of any of these three roles: an administrator, an operator, or a reader can all be assigned as signers.