Accounts and access
This section is for the people who administer Kuumba for an organisation. Everything above it is written for the people using it.
Accounts
Section titled “Accounts”Access is managed centrally. A person can sign in only once their account has been created and given access — there is no self-service sign-up, and a user cannot grant themselves anything.
That means two things in practice:
- Starting someone is an administrative act, not an invitation they accept.
- Stopping someone is immediate and complete. Revoke the account and every session, chat and connector belonging to it stops working.
What you control
Section titled “What you control”- Which models are available, and which is the default.
- Which capabilities exist at all: web search, memory, artifacts, file upload, sharing, temporary chats.
- Which apps can be connected, and whether users connect them themselves.
- Who can build and share bots beyond their own account.
Reviewing access
Section titled “Reviewing access”Review three things on a schedule rather than on an incident:
- Accounts — leavers, and people whose role has changed.
- Connected apps — every connector is a standing grant to a real mailbox or drive.
- Shared links — they are public to anyone holding the URL.