About User Roles
Skykit roles work in two layers. Account roles decide who can manage your Account and Tenants. Product rules device what someone can actually do inside a Tenant such as uploading content, organizing it, or putting it on a screen. This guide walks through both, organized around who should have each role and why, not just the boxes they check.
For more information on adding users, configuring user roles, and granular permissions each role has, see these pages:
Roles at a Glance
Not seeing products or features?
Access to to some features also depends on your Accounts edition (Enterprise, Pro, or Basic plan).
Role | Role Type | One Line Description | Best For | Recommended Count |
|---|---|---|---|---|
Account Owner | Account | Owns the whole Account across all Tenants. Can create Tenants and add users. | Your company-wide Skykit admin. | 1-2 people |
Account Tenant Admin | Account | Owns one or more specific Tenant(s). Can add existing Account users to Tenants(s). | A regional, site, or department lead. | 1-3 people per Tenant |
Account User | Account | Access to one more more specific Tenant(s). | Everyone else — access depends on product role. | Most of your team |
Administrator | Product (Beam, Control) | Full access to specific Tenant(s). | Person responsible for hardware/network at a specific site | 1-3 people per Tenant |
Display Manager | Product (Beam) | Access to functionality other than Display pairing and delete, App Management, and credential management. | Day-to-day operations and troubleshooting lead | As needed |
Content Manager | Product (Beam) | Access to create content and organize it in Playlists and Collections. View only access to Displays. | Content strategist/corporate comms owners | As needed |
Content Organizer | Product (Beam) | Access to organize content in Collections and Playlists. No content creation or Displays access. | Scheduling coordinator working from a shared library | As needed |
Content Creator | Product (Beam) | Access to create content. No Collections, Playlists, or Displays access. | Designer, marketer, or outside agency contributor | As needed |
Restricted Installer (beta/available by request) | Product (Control) | Limited view of Control showing device information and screenshot functionality. | Installers who need information to set up devices | As needed |
Account Roles
Account roles determine what a user can manage at the Account and Tenant-administration level. This is separate from what they can do with Content and Displays day-to-day.
Account Owner
Best for: The one or two most trusted people responsible for Skykit company-wise, typically an IT director, AV lead, or digital signage program owner.
What they can do: Create new Tenants, add new users to the Account, and automatically receive Administrator access to all Tenants, no extra setup required.
Recommended count: 1-2 people. Keeping this small avoids confusion about who’s ultimately responsible if something changes across the Account.
Example: A company with one central IT team managing Skykit for the whole organization would have the team lead be Account Owner.
Account Tenant Admin
Best for: A regional manager, site lead, or department head responsible for Skykit at their specific location(s), not the whole company.
What they can do: Assign existing Account users to the Tenants they manage, give them a product role, and adjust tenant level settings like name and time zone. Cannot create new users or Tenants.
Recommended count: 1-3 people per Tenant, so there’s a clear point of contact without being a single point of failure.
Example: A national retailer with one Account Owner at HQ and a Tenant Admin at each regional office, each managing their own team signage independently.
Account User
Best for: Anyone added to a Tenant who doesn’t need Account or Tenant administration responsibilities.
What they can do: Nothing at the Account level. Their capabilities inside a Tenant come entirely from the product role they’re assigned.
Recommended count: Most of your team will fall here.
Example: A store employee who’s given a Content Creator role at their location. They can upload photos of in-sore promotions but have not admin responsibilities.
Restricted Installer (beta/available by request)
Best for: Someone responsible for installing and configuring WiFi on a devices who does not need to manage content.
What they can do: Nothing at the Account level. Their capabilities inside a Tenant come entirely from the product role they’re assigned.
Recommended count: As needed.
Example: A third party installer hired to install devices and connect them to the Internet, then send a screenshot to show that the device is working correctly.
Product Roles
Product roles determine what a person can do inside a Tenant.
Have different needs for different Tenants?
While a user can only have one Account role, they can have different product roles for each Tenant.
Administrator
Best for: The person responsible for the hardware and network for a Tenant. Only available to users with the Account role of Account Owner or Account Tenant Admin.
What they can do: Access all features in Skykit Beam and Skykit Control.
Recommended count: 1-3 per Tenant.
Example: The onsite IT or AV person who both curates content and physically sets up new screens.
Display Manager
Best for: An operations or support lead who handles content, displays, and troubleshooting but isn’t setting up new devices.
What they can do: All Beam functionality except for pairing and deleting displays, App Management, and managing credentials.
Recommended count: As needed.
Example: An ops coordinator who creates and curates content and changes content on Displays.
Content Manager
Best for: Someone who owns content strategy, building and organizing what plays without needing to touch a specific screen.
What they can do: Full content control: creating, editing, deleting, and sharing content. Creating and managing Playlists and Collections, plus access a limited Displays view where they can see Screenshots and Live View but not edit Display settings or change content.
Recommended count: As needed.
Example: A corporate communications manager who builds and shares Playlists company-wide, relaying on local teams to get that content onto their screens.
Content Organizer
Best for: Someone who arranges already-approved content rather than sourcing new assets. A good fit when content creation and content scheduling are split between teams.
What they can do: Can add/remove existing content to and from Playlists and Collections, manage Play Rules, and manage labels. Cannot upload new content and has no Displays access.
Recommended count: As needed.
Example: Corporate uploads all approved videos; a regional scheduling coordinator arranges those existing assets into the right Playlists for their site and uses Play Rules to determine when and where the content will play.
Content Creator
Best for: A designer, marketer, or outside contributor who should only add assets, not control scheduling or screens.
What they can do: Upload new content into the Tenant’s library. Cannot build or edit Playlists and Collections and has no Displays access.
Recommended count: As needed.
Example: An external design agency contributing new video assets with no say in when or where they play.
Basic (Legacy/deprecated)
This was the original catch-all Beam role before the more granular roles above existed. It can no longer be newly assigned, but you may see it as a role for an existing user.
Restricted Installer (beta/available by request)
Best for: Someone responsible for installing and configuring WiFi on a devices who does not need to manage content.
What they can do: Access a mostly read-only version of Control with information about devices and the ability to take and download screenshots. Users with this role can only be given a product role of Restricted Installer.
Recommended count: As needed.
Example: A third party installer hired to install devices and connect them to the Internet, then send a screenshot to show that the device is working correctly.