Roles, Permissions, Packages, and Licenses in Newforma Konekt

6 minutes
15 hours ago

Every user in Newforma Konekt has two roles: a hub role, which governs hub-level permissions, and a project role, which governs permissions within a specific project.

The package assigned to a hub sets which activity centers are potentially available to that hub’s users. From there, each user’s combination of hub role and project role narrows down what they can actually do within the hub and its projects.

How Packages Work

The package assigned to a hub determines which activity centers are available to users on that hub.

Newforma Konekt currently supports three main packages:

  • Info Track: Base package required for every hub.
  • BIM Track: Add-on for BIM-related activity centers.
  • CA Track: Add-on for contract administration activity centers.

Packages take precedence over project role permissions. For example, a project’s Editor or Admin, who has the permission by default to work in the viewer, cannot do so if the hub doesn’t have the BIM Track add-on.

For a detailed breakdown of the features and activity centers included in Info Track and each add-on, see Newforma Konekt packages.

How Roles Work

Every user holds two roles at all times: one at the hub level and one at the project level.

Hub Roles

A hub role is one of the two roles every user holds (the other being their project role).

A hub role determines whether a user can manage hub-level settings, invite users to the hub, create projects, and access the subscription page, among other

There are three hub roles:

  • Hub Owner: Assigned to the creator of the hub. Can perform every hub management function, namely all actions across every page under Hub Menu.
  • Hub Admin: Can perform user and project management functions for the hub. Can access every page under Hub Menu, but can’t perform every action in them.
  • Guest: Cannot perform any actions at the hub level. Cannot access the pages under Hub Menu.

Each hub can have only one Hub Owner. They’re automatically added to every project in the hub with Admin-level (project role) permissions.

Permissions of Hub Roles

The table below breaks down hub role permissions in more detail.

PermissionHub OwnerHub AdminGuest
Delete hub  
Add/remove users 
Import users into a project with a CSV file 
Create/delete projects 
Access the subscription page 
Whitelist internal user domains for project access 
Enforce Microsoft SSO 
Generate API access token  

Hub roles are independent of project roles. For example, a Hub Admin can add users to a project even if they’re not part of it. Conversely, a Guest may have no hub-level permissions at all but hold full administrative control within a project.

Project Roles

A project role is the other of the two roles every user holds, alongside their hub role.

A project role determines what a user can see and do within a specific project (i.e., whether they can access or work within an activity center). A user can have a different project role for each project in the hub.

There are five project roles:

  • Reviewer: Can access shared items and weigh in on project decisions that need their input. Cannot access activity centers outside their workflow.
  • Reader: Provides view-only access. Can see and download content from all activity centers but can’t work in them.
  • Editor: Provides broad working access for day-to-day project contribution. Can create and manage project content and respond to items that need their input, but can’t perform project administration functions.
  • Admin: Can perform all Editor-level actions, plus project administrative functions.
  • Creator: Has the same permissions as Admin, and is automatically assigned to the user who creates the project. Can also assign other users within the project as Admins.
Permissions of Project Roles

A user’s project role determines which activity centers they have access to and what they can do within them. See the permission structure of each project role for each activity center:

Hub Owners and Hub Admins can also see the permission structure of each project role for each activity center in Newforma Konekt’s Roles and permissions page.

Project roles are independent of hub roles. For example, a user with Admin access across all projects may have no administrative permissions at the hub level. Conversely, a user may have only view-only access at the project level while holding the Hub Admin role.

How Licenses Work

A license is required for any user whose combination of hub role and project role is not Guest (hub role) and Reviewer (project role) across every project they have access to. Users assigned the Guest hub role and the Reviewer project role on all of their projects do not require a license.

Any other combination of roles — including Reader, Editor, or Creator/Admin project roles, or Hub Owner or Hub Admin hub roles — requires a license.

Licenses are purchased with an Info Track subscription, plus any BIM Track or CA Track add-ons you select, in the quantity your organization needs.

Hub Owners and Hub Admins can track their hub’s license usage through Newforma Konekt’s Subscriptions page.

Whitelisted users are assigned the Reader role by default and consume a license — even if they aren’t added to a specific project.

Putting It All Together

The following examples show feasible combinations of package, hub role, and project role, and how they combine to determine access and license requirements. These are not fixed pairings, as any package, hub role, or project role can combine with any other.

ScenarioHub PackageHub RoleProject RoleLicense RequiredResulting Access
External consultant reviewing shared itemsAny†GuestReviewer on the projects they have access toNoCan view and respond only to items shared or forwarded to them. Cannot access most activity centers, including the viewer.
BIM modelerInfo Track + BIM Track + CA TrackGuestEditor on the projects they have access toYesCan log RFIs, submittals, and change management items, and work in the viewer. Cannot manage project settings or archive issues, and cannot access hub settings.
BIM modeler on a hub without BIM TrackInfo Track + CA TrackGuestEditor on the projects they have access toYesCan log RFIs, submittals, and change management items but cannot access the viewer, because the hub’s package doesn’t include BIM Track.
Internal project managerInfo Track + BIM Track + CA TrackHub AdminCreator on the projects they have created; Admin on othersYesFull project-level access, including managing project settings and archiving issues, plus hub-level access to invite users and create projects. Cannot delete the hub.
Anonymous whitelisted readerAny†GuestReader on all limited projects in the hubYesCan access and view the activated activity centers of all limited projects. Excluded from all workflows.

†The hub’s package is not relevant to the scenario.

Related Items