Kissmetrics User Management | OpsBlu Docs

Kissmetrics User Management

Manage user roles, permissions, and team access in Kissmetrics — step-by-step admin guide.

Overview

Kissmetrics user management allows you to control who has access to your analytics data, reports, and settings. Proper user management is critical for maintaining security, ensuring compliance, and enabling your team to effectively use behavioral analytics for data-driven decision making.

This guide provides a comprehensive overview of user management capabilities in Kissmetrics, including permission levels, best practices, and links to detailed guides for specific tasks.

Why User Management Matters

Security: Limit access to sensitive customer data and business metrics to authorized personnel only.

Compliance: Meet regulatory requirements (GDPR, SOC 2, HIPAA) by controlling and documenting who can access personal data.

Collaboration: Enable team members to access the insights they need without overwhelming them with unnecessary features or data.

Accountability: Track who makes changes to tracking implementation, reports, and settings through audit logs.

Productivity: Ensure team members have appropriate access levels to perform their jobs effectively.

Permission Levels

Kissmetrics offers several permission levels to match different user roles and responsibilities.

Owner

Full Control: Complete access to all features, data, and settings.

Capabilities:

  • Manage billing and subscriptions
  • Add, edit, and remove team members
  • Access all projects and reports
  • Configure tracking and integrations
  • Modify account settings
  • Delete or transfer account

Typical Roles:

  • CEO or business owner
  • VP of Analytics or Data
  • Account administrator

Limitations:

  • Usually only one Owner per account
  • Cannot be removed by other users
  • Must transfer ownership to remove

Admin

Management Access: Can manage users and settings but not billing.

Capabilities:

  • Add, edit, and remove users (except Owner)
  • Configure tracking implementation
  • Create and manage integrations
  • Access all projects and reports
  • Modify account settings
  • Create and modify dashboards

Cannot Do:

  • Manage billing or subscriptions
  • Remove or modify Owner permissions
  • Delete the account

Typical Roles:

  • Analytics Manager
  • Product Manager
  • Engineering Lead
  • Marketing Operations

User

Standard Access: Can create and view reports but cannot manage settings or users.

Capabilities:

  • View all reports and dashboards
  • Create personal reports and dashboards
  • Export data
  • Comment and collaborate on reports
  • Receive report notifications
  • Access assigned projects

Cannot Do:

  • Manage other users
  • Modify tracking settings
  • Configure integrations
  • Change account settings
  • Manage billing

Typical Roles:

  • Marketing Analyst
  • Product Analyst
  • Data Analyst
  • Marketing Manager
  • Product Manager

Read-Only

View-Only Access: Can view reports but cannot create or modify anything.

Capabilities:

  • View existing reports and dashboards
  • Access assigned projects
  • Comment on reports (if enabled)
  • Receive report notifications

Cannot Do:

  • Create new reports or dashboards
  • Modify existing reports
  • Export data
  • Change any settings
  • Manage users

Typical Roles:

  • Executive leadership
  • Stakeholders
  • Clients (for agencies)
  • Occasional viewers
  • Contractors with limited needs

Permission Matrix

Action Read-Only User Admin Owner
View Reports
Create Reports
Edit Reports Own Only
Delete Reports Own Only
Export Data
Create Dashboards
Share Reports
Comment on Reports ✓*
View All Projects Assigned
Configure Tracking
Manage Integrations
Add Users
Edit User Permissions
Remove Users
Modify Account Settings
Manage Billing
Transfer Ownership
Delete Account

*May be restricted by Admin settings

User Management Tasks

Adding Users

Invite new team members to access your Kissmetrics account:

Process Overview:

  1. Navigate to Settings → Team
  2. Click Invite User
  3. Enter email address
  4. Select permission level
  5. Assign to projects (if applicable)
  6. Send invitation

See Full Guide: Add User Access

Updating User Permissions

Modify existing user access levels as roles change:

Common Scenarios:

  • Promoting User to Admin
  • Downgrading Admin to User
  • Temporary elevated access
  • Project reassignments

See Full Guide: Update User Access

Removing Users

Revoke access when team members leave or no longer need access:

Key Considerations:

  • Remove access on or before last day of employment
  • Transfer ownership of reports and dashboards
  • Document removal for compliance
  • Handle different scenarios (termination, contractor completion, security incident)

See Full Guide: Remove User Access

Best Practices

Security Best Practices

Principle of Least Privilege:

  • Grant users the minimum access needed for their role
  • Start with lower permissions and upgrade as needed
  • Regularly review and downgrade unnecessary elevated access

Access Reviews:

  • Conduct quarterly user access reviews
  • Remove inactive users (no login in 90+ days)
  • Verify permissions match current roles
  • Document review outcomes

Offboarding Process:

  • Remove access on or before last day of employment
  • For security incidents, remove immediately
  • Transfer ownership of reports before removal
  • Keep records of access removal

Strong Authentication:

  • Enable Single Sign-On (SSO) if available
  • Require strong passwords
  • Enable multi-factor authentication (MFA)
  • Monitor for suspicious login activity

Role-Based Access Control

Assign permissions based on job function:

Marketing Team:

  • Permission: User
  • Access: Marketing project
  • Can create campaign reports and dashboards

Analytics Team:

  • Permission: Admin
  • Access: All projects
  • Can configure tracking and manage integrations

Executive Team:

  • Permission: Read-Only or User
  • Access: Executive dashboards
  • Can view key metrics without creating reports

IT/Engineering:

  • Permission: Admin
  • Access: Technical implementation
  • Can manage tracking code and integrations

Finance:

  • Permission: Owner (for billing) or Read-Only (for viewing)
  • Access: Revenue and financial reports

Compliance and Governance

Documentation Requirements:

  • Maintain list of all users and their permissions
  • Document reason for access (job role)
  • Keep records of permission changes
  • Log user additions and removals

Audit Trail:

  • Track who made changes and when
  • Document approvals for access requests
  • Maintain records for required retention period
  • Be prepared for compliance audits

Data Protection:

  • Limit access to personal data to those who need it
  • Train users on data protection obligations
  • Implement data retention and deletion policies
  • Ensure users understand GDPR, CCPA, or other relevant regulations

Separation of Duties:

  • Don't grant everyone Admin access
  • Separate billing (Owner) from operational access
  • Distribute Admin responsibilities among multiple people
  • Implement approval workflows for sensitive changes

Multi-Project Management

For organizations with multiple Kissmetrics projects:

Project-Level Access

Benefits:

  • Limit users to relevant projects only
  • Separate client or brand access for agencies
  • Maintain data segmentation
  • Simplify user experience

Implementation:

  1. Create separate projects for different brands/products
  2. Assign users to specific projects
  3. Users only see data for assigned projects
  4. Maintains data isolation

Use Cases:

  • Agencies managing multiple clients
  • Multi-brand organizations
  • Companies with distinct product lines
  • Separating production from test environments

SSO and Advanced Authentication

Single Sign-On (SSO)

Benefits:

  • Centralized user management
  • Automatic provisioning and deprovisioning
  • Enhanced security
  • Simplified login experience
  • Compliance with corporate security policies

Supported Protocols:

Configuration:

  1. Contact Kissmetrics to enable SSO
  2. Configure your identity provider (Okta, Azure AD, etc.)
  3. Map user attributes and permissions
  4. Test SSO connection
  5. Enable for all users

Multi-Factor Authentication (MFA)

Why MFA:

  • Adds layer of security beyond passwords
  • Protects against compromised credentials
  • Required for many compliance frameworks
  • Industry best practice

Setup:

  1. Enable MFA in account settings
  2. Users configure MFA on next login
  3. Support authenticator apps (Google Authenticator, Authy)
  4. Backup codes for account recovery

Troubleshooting Common Issues

User Cannot Log In

Possible Causes:

  • Invitation not accepted
  • Account locked or disabled
  • Incorrect password
  • SSO configuration issue

Solutions:

  1. Verify user is in team member list
  2. Check if invitation is still pending
  3. Resend invitation if needed
  4. Reset password or check SSO settings

User Has Wrong Permissions

Issue: User cannot access needed features or data

Solutions:

  1. Review user's permission level
  2. Check project assignments
  3. Update permissions if needed
  4. Ask user to log out and back in

Cannot Add More Users

Issue: Reached user limit for plan

Solutions:

  1. Remove inactive users to free seats
  2. Upgrade to plan with more user seats
  3. Contact Kissmetrics sales

Removed User Can Still Access

Issue: User access persists after removal

Solutions:

  1. Verify removal was saved
  2. Try removing again
  3. Ask user to log out completely
  4. Contact Kissmetrics support if issue persists

User Management Workflow

Standard Operating Procedure

New User Request:

  1. Receive request (email, ticket, form)
  2. Verify requestor authorization
  3. Determine appropriate permission level
  4. Get manager approval if required
  5. Add user to Kissmetrics
  6. Document addition
  7. Notify user and provide onboarding

Permission Change Request:

  1. Receive change request
  2. Verify reason for change
  3. Get appropriate approval
  4. Update permissions
  5. Notify user of change
  6. Document change

User Removal:

  1. Receive removal request (HR, manager)
  2. Verify authorization
  3. Identify reports to transfer
  4. Transfer ownership
  5. Remove user access
  6. Verify removal successful
  7. Document removal

Automation

Integration with HR Systems:

  • Automatic user provisioning on hire
  • Automatic deprovisioning on termination
  • Sync user attributes (name, email, department)
  • Reduce manual work and errors

SCIM Provisioning:

  • Centralized user management
  • Automated access control
  • Real-time synchronization
  • Enhanced security

Detailed Guides

For step-by-step instructions on specific user management tasks:

Key Takeaways

  1. Choose Appropriate Permissions: Assign the minimum access needed for each user's role
  2. Review Regularly: Conduct quarterly access reviews to ensure permissions remain appropriate
  3. Onboard Properly: Provide new users with training and documentation
  4. Offboard Promptly: Remove access immediately when team members leave
  5. Document Everything: Maintain records for compliance and audit purposes
  6. Use SSO When Available: Centralize user management and enhance security
  7. Monitor Activity: Track user actions through audit logs
  8. Communicate Changes: Notify users when their access is modified

Effective user management in Kissmetrics balances accessibility with security, ensuring your team can leverage behavioral analytics while protecting sensitive data and maintaining compliance.