Admin
The governance role. It manages users, companies, technical settings, and the approval policy rules — but it cannot initiate or sign a transfer. It can approve one that someone else initiated, and to do that it signs with its passkey (or with the email code, if Koywe enabled it for your organization). That separation is on purpose.
Can / cannot
- View everything: transactions, balances, reports
- Create their passkey, which they need to approve and to save changes to the rules
- Invite users and assign roles
- Create and remove companies in the organization
- Change the approval policy rules, if a Super Admin user enabled it for them
- Approve pending operations
- Manage the organization’s passkeys
- Create and delete API credentials, configure webhooks
- Submit the KYB documentation
- Initiate payments, withdrawals, or conversions
- Sign transfers
- Manage the company’s own bank accounts and wallets
- Manage contacts and their accounts
When to use it
For whoever manages the account without touching the money: the head of IT, of compliance, or whoever manages the team’s access.
Having the permission is not enough to edit the approval policy. The rule that allows managing it is only created automatically for Super Admin users. An Admin user passes the permission check, but the approval policy denies them, until a Super Admin user writes a Policy management rule that allows it.
Next steps
- Treasury Manager — the other side of the split: moves the money and does not touch the rules.
- Approval policy — what an Admin user manages; the details are in no rules, no operations.
- If they open the screen and cannot save: I cannot edit the approval policy.