KMD Agency uses five roles. Every permission check in the platform goes through a named permission, never a role name directly — roles are just named bundles of permissions.
| Role | Access |
|---|---|
| Super Admin | Every permission — the only role that can manage licensing, updates, team members, and platform-wide settings. |
| Admin | Projects, clients, website content, products, orders, and analytics — everything except team management and platform-level settings. |
| Project Manager | Projects and clients, but not the website, commerce, or platform settings. |
| Developer | Can view and update projects they’re assigned to. No client, commerce, or settings access. |
| Client | Their own projects only, through the separate Client Portal. |
Assignment-scoped, not blanket
A Developer without the “manage all projects” permission only ever sees projects they’re specifically assigned to — not every project in the system. The same scoping applies to project files and internal messages.
Managing your team
As a Super Admin, go to Team to invite staff, assign roles, and deactivate accounts. Invitations are sent by email with a single-use link — accepting one signs the new team member in directly, without an additional OTP step, since the invite link itself already proves the recipient controls that inbox.