Team Access Control
Give each team member the right level of access to Hiring, Security, Outreach, Training, and Performance, and audit or revoke it when they leave.
Why It Matters
Not everyone on your team needs to see everything. Your recruiter doesn’t need vulnerability reports; your security lead doesn’t need outreach campaigns. Team access control lets you decide, per person and per product, who can view, who can manage, and who stays out, and gives you a single page to answer “what exactly can this person access?” when audit or offboarding time comes.
Products and Access Levels
Kit has five products: Hiring, Security, Outreach, Training, and Performance. Each team member gets one access level per product:
| Level | What it means |
|---|---|
| No access | The product is off-limits. Opening it shows an access-denied screen with a way to request access. |
| Member | Standard day-to-day access: view and work with the product’s content, subject to any per-item assignments (e.g., restricted job postings). |
| Admin | Full control of that product: create, configure, and manage everything in it, without needing per-item assignments. |
If you never set a level for someone, they’re a Member. Existing team members keep working as before; nothing gets locked out until you decide to change it.
Account Admins sit above product levels: they see every product, access everything, and are the only ones who can change an existing member’s access. An Admin can also hand out the invite members capability, which lets that person set the access of the teammates they invite, never above their own.
Note
Product levels control access to a whole product. Within a product, finer-grained assignments still apply; for example, restricted job postings are visible to their assigned hiring team, account admins and Hiring admins. See Inviting Your Team for how job-level roles work.
Note
Finance is the exception to the product matrix. A Finance member starts with No access in all five products, but can use the focused Finance workspace for candidate payouts, researcher disbursements, and W-8/W-9 review. Those queues expose payment context, not candidate applications or vulnerability-report content. See Team Roles.
The Modules Matrix
Go to Settings → Team → Modules for the whole-team view: one row per member, one column per product. Pick a level in any cell and it applies immediately.
Two shortcuts speed this up:
- Roles: each row has a quick-picker with predefined team roles like Recruiter, Finance, Security Analyst, Growth, Trainer, or People Lead. Picking one fills sensible levels across all five products in one click; you can still adjust individual cells afterwards.
- Account admin toggle: flipping it grants full access to everything and collapses the row, since per-product levels no longer apply.
Tip
Start from a role, then tweak. Roles encode the levels most teams use: Recruiter gets Hiring admin plus member access to Outreach, Training, and Performance; Security Analyst gets Security admin plus Training and Performance. It’s faster and less error-prone than setting each module by hand. See Team Roles for what each role covers.
The Member Access Page
For a single-person deep dive, go to Settings → Team → Members and click a member. Their access page shows:
- Role: their team role, from full Admin down to Member
- Product levels: their level for each of the five products, editable in place
- Invite members: a toggle that lets this person invite teammates at or below their own access, without making them an Admin. See Inviting Your Team
- Access ledger: a read-only list of their assignments and individual grants: which job postings, which reports, which campaigns, and since when
Reading the access ledger
The ledger collects assignments and individual grants across five products. It is not a complete list of every open item the person can view through module access. Each entry names the item, the product it belongs to, and the date access was granted. Use it to:
- Prepare for a security or compliance audit
- Double-check a contractor only sees what they should
- Review everything a departing member touches before offboarding
To restrict a single report or campaign to a chosen few and grant them a view or manage role on it, see Item-Level Access.
Requesting Access
When a member opens a product they don’t have access to, they see an access-denied screen. It includes a one-click Request access button that notifies all Account Admins. The admin can then grant a level from the Modules matrix or the member’s access page.
Offboarding a Member
When someone leaves, open their member access page. You have two options:
| Action | What happens |
|---|---|
| Revoke all access | Keeps their seat but strips every product level and every individual grant in the ledger. Good for leave-of-absence or role changes. |
| Remove from account | Removes them from the team entirely. |
Either action also clears the invite members capability, so a delegated inviter loses it along with their product levels.
If the person is the sole hiring manager on a posting or assigned to an active report, Kit requires a choice: pick a successor or explicitly leave the item unassigned. Only then does it revoke access or remove the member. The account owner cannot be revoked or removed through this flow.
Warning
Revocation strips everything at once and doesn’t keep an undo list. After “Revoke all access”, the member’s individual grants are gone; restoring them means re-adding each one by hand. Review their access ledger before revoking, and choose successors carefully during reassignment: once ownership moves, the previous owner is detached from those items.
Do / Don’t
| Do | Don’t |
|---|---|
| Use roles to set levels consistently across similar people | Set every module manually when a preset role matches the person’s responsibilities |
| Review the access ledger before offboarding | Remove a member blind; sole-owned items will force a reassignment prompt anyway |
| Use “Revoke all access” for leave or role changes | Remove someone from the account when they’re coming back |
| Leave levels unset for members who need standard access | Set “No access” everywhere as a default; that’s what revoke is for |
Quick Checklist
- Open Settings → Team → Modules and review every member’s row
- Apply roles for common jobs, then fine-tune individual cells
- Flip the account admin toggle only for people who manage the team
- Spot-check a member’s access page and ledger to confirm it matches expectations
- Tell your team about the Request access button so denials don’t become support tickets
- At offboarding: review the ledger, pick “Revoke all access” or “Remove from account”, and assign successors for sole-owned items