Skip to Content

Root user

The root user is not a role

It is not granted or picked from a list: it is the user who registers the organization with Koywe, and the first thing they must do is create their passkey. There is only one, it is permanent, and only Koywe can step in afterward.

It is the owner of security: the master key from which everyone else is enabled. Without it, no one else can create their passkey.

Can / cannot

Can
  • Enable the organization to sign, by creating their passkey
  • Approve the passkey of each person who joins
  • Help recover the passkey of someone who got locked out
  • Approve invitations for users with sensitive permissions
  • Operate and change the approval policy rules, if they also have the role
Cannot
  • Give away or transfer their root status
  • Sign on behalf of another person
  • Recover their own passkey if they lose it — Koywe does that
  • Skip the approval policy: it applies to them too
  • Approve their own operations

Who to choose

Because it is tied to whoever does the onboarding, decide it before you start the request.

We recommend that this spot goes to a trusted person with formal responsibility in the company (a legal representative, a partner, or the head of finance). The rest of the team depends on their passkey to operate.

It is a dependency worth documenting

If the root user leaves the company or loses their device, no one else can register or recover passkeys until Koywe steps in. Let Koywe know as soon as that person changes role or team.

Next steps

Last updated on