Skip to Content

Viewer

Read-only access to the whole platform. It views, exports, and looks things up — it does not change anything.

Can / cannot

Can
  • View transactions, balances, and reports
  • View contacts and their accounts
  • View the organization’s users and their roles
  • View the approval policy and pending operations
  • View webhooks and their events
Cannot
  • Initiate any operation
  • Create or edit contacts
  • Invite users
  • Approve operations or change their rules
  • Create their own passkey
  • View the security logs
A Viewer user cannot create a passkey, and that is fine

They never sign anything, so they do not need one. If you expected the whole team to register, this is the role left out on purpose.

When to use it

For accounting, auditing, an external partner, or anyone who needs to look without any risk of changing things. It is the only role you can invite without the invitation waiting for the root user’s approval, so it is also the fastest to set up.

Next steps

  • API users — the last one on the list: how a system operates, without a passkey.
  • Operator — the next step up, when someone also needs to initiate operations.
Last updated on