Skip to main content

Users: Registration, Deletion, and Permissions

In POK Proof of Knowledge, you manage your team from the Team Members section. Administrators can invite new users with an administrator, operator, or reader role, and can also remove members or grant the signer permission. This guide walks you through those tasks and explains what each role and permission allows.

Open the Team Members section

  1. In the top navigation bar, on the right side, click your organization's name.
  2. Click "Team Members".

Add a new member

If you have administrator permissions, the first thing you see on this screen is the option to add a new member.

  1. In the pop-up window, enter the new user's email address.
  2. Select the role for the new user: administrator, operator, or reader.
  3. Choose the language of the invitation.
  4. Click "Invite".

POK then sends an email to the new user. They can access your organization by clicking "Go to the organization".

What roles can I assign, and what does each one do?

Every member has one of three roles:

  • Administrator: full access, including inviting or removing team members, issuing credentials, and managing integrations.
  • Operator: can create and preload credentials, but cannot issue them directly or manage team members.
  • Reader: read-only access, for members who only need to view credentials, designs, and reports.

What is the signer permission?

Independent of their role, any member can also be granted the signer permission. A signer can digitally sign the credentials that require a signature, or reject signature requests. To assign it, click the pencil icon next to a member in the list, check "Assign signer role", and confirm.

Remove a member

Above the member list you will see counters for Members, Administrators, Operators, and Signers, followed by the list of members with their details. If you have administrator permissions, you can also delete a member from this list.

When you click the delete icon, POK asks you to confirm the removal. Once you confirm, the user is removed immediately and, if they try to log in afterwards, they will no longer have access.

Permissions for each role

FunctionalityAdministratorOperatorReader
Design credentialsYesYesView only
Issue credentialsYesNo, they can only preloadNo
Bulk sending or rejectionYes, their own or preloadedNo, they can only reject the ones they createdNo
IntegrationsYes: use available applications, add new ones, or delete themNoView only
MembersAdd or delete membersNoNo

The signer permission works on top of any of these three roles: an administrator, an operator, or a reader can all be assigned as signers.