User roles
Every person who joins your organization gets a role. The role decides two things:
- What they can do — operate, approve, change the approval policy rules, manage users.
- Which views they can access — the interface only shows what the role allows. When someone cannot find a button, the cause is almost always there, not a bug.
There are five roles, from view-only to managing everything.
Access by role
| Super Admin | Admin | Treasury Manager | Operator | Viewer | |
|---|---|---|---|---|---|
| View everything: transactions, balances, reports | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create their own passkey | ✓ | ✓ | ✓ | ✓ | — |
| Initiate payments and withdrawals | ✓ | — | ✓ | ✓ | — |
| Manage contacts and their accounts | ✓ | — | ✓ | ✓ | — |
| Sign transfers | ✓ | — | ✓ | — | — |
| Approve pending operations | ✓ | ✓ | ✓ | — | — |
| Manage the company’s own accounts and wallets | ✓ | — | ✓ | — | — |
| Invite users and assign roles | ✓ | ✓ | — | — | — |
| Change the approval policy rules | ✓ | ✓ | — | — | — |
| Manage the organization’s passkeys | ✓ | ✓ | — | — | — |
| Create companies and API credentials | ✓ | ✓ | — | — | — |
Next steps
- Root user — who becomes root, why it is not a role, and why you should decide it before onboarding.
- Each role’s page: Super Admin, Admin, Treasury Manager, Operator, Viewer, and API users.
- Passkeys — the role enables, the passkey confirms: without it, the role is not enough.
Last updated on