Understand roles and permissions
The four roles, what each one can do, and the separation-of-duties rules that cannot be switched off.
Version 1.0 · Last updated
When you would read this
Read this before you invite anyone, and whenever you are deciding what access a new joiner should have.
The four roles
Everyone in your organisation has exactly one role.
Admin. Governance and configuration. The only role that can change the team, the policies, the wallets and the company settings. Holds a signing key and can sign payments.
Signer. Validates and executes money movement. Can create and sign payments, but cannot change the rules they operate under. Holds a signing key.
Requester. Prepares work: payment requests, invoices, counterparties. Holds no signing key and can never move money.
Viewer. Read-only visibility across the workspace, and nothing else.
What each role can do
| Capability | Admin | Signer | Requester | Viewer |
|---|---|---|---|---|
| View everything | Yes | Yes | Yes | Yes |
| Create payment requests and batches | Yes | Yes | Yes | No |
| Sign and approve payments | Yes | Yes | No | No |
| Add and edit counterparties, create invoices | Yes | Yes | Yes | No |
| Send bank transfers | Yes | Yes | No | No |
| Create and configure wallets | Yes | No | No | No |
| Create, edit and publish policies | Yes | No | No | No |
| Invite or remove members, change roles | Yes | No | No | No |
| Activate banking, manage banking settings | Yes | No | No | No |
| Reveal card details | Yes | No | No | No |
| Emergency lock | Yes | No | No | No |
| View audit log and export evidence | Yes | Yes | Yes | Yes |
Anything not listed for a role is blocked. Access is denied by default.
Rules that cannot be switched off
These are enforced by the platform, not by the screen you are looking at. Changing what your browser displays does not change what you are allowed to do.
- Admin cannot be invited. Invitations can only grant Signer, Requester or Viewer. The person who sets the organisation up is the Admin.
- Admins are protected. Only an Admin can remove an Admin, the last Admin can never be removed or demoted, and nobody can change their own role.
- Signers cannot rewrite the rules. A Signer can approve a payment but cannot edit the policy that governs it.
- No self-approval above your limit. If the person who requested a payment is also a signer, anything above your self-approval limit needs a second, independent signature.
- Requesters and Viewers hold no key. No configuration can give them the ability to sign.
Common problems and what they mean
"The Sign button is missing." You are a Requester or a Viewer, or the payment is blocked. Only Admins and Signers can sign.
"I cannot edit policies." Only Admins can. Ask an Admin.
"I cannot change my own role." Nobody can. Ask another Admin.
