Root user
It is not granted or picked from a list: it is the user who registers the organization with Koywe, and the first thing they must do is create their passkey. There is only one, it is permanent, and only Koywe can step in afterward.
It is the owner of security: the master key from which everyone else is enabled. Without it, no one else can create their passkey.
Can / cannot
- Enable the organization to sign, by creating their passkey
- Approve the passkey of each person who joins
- Help recover the passkey of someone who got locked out
- Approve invitations for users with sensitive permissions
- Operate and change the approval policy rules, if they also have the role
- Give away or transfer their root status
- Sign on behalf of another person
- Recover their own passkey if they lose it — Koywe does that
- Skip the approval policy: it applies to them too
- Approve their own operations
Who to choose
Because it is tied to whoever does the onboarding, decide it before you start the request.
We recommend that this spot goes to a trusted person with formal responsibility in the company (a legal representative, a partner, or the head of finance). The rest of the team depends on their passkey to operate.
If the root user leaves the company or loses their device, no one else can register or recover passkeys until Koywe steps in. Let Koywe know as soon as that person changes role or team.
Next steps
- Super Admin — the highest role in the product, which is not the same as being root.
- Passkeys — the root user’s passkey is the first thing to create.
- If the root user is gone or cannot approve: I am a Super Admin user and cannot approve passkeys for my team.