Roles and Permissions
One permission registry governs every guarded action. This page lists the built in roles, what each one grants, and the full catalog of 129 permissions. It is generated from the registry, so it cannot drift.
resource.action permission. Roles are named bundles of permissions. A tenant can also define custom roles from the same catalog.Built in roles
| Role | What it does | Grants |
|---|---|---|
owner | Full control of the tenant. Holds every non platform permission. | all non platform permissions |
admin | Administers the tenant. Holds every non platform permission. | all non platform permissions |
compliance_officer | Reviews compliance cases, holds and releases account holders, reads the audit and approval trail. | 24 permissions |
customer_service | Front line support. Reads payments and escrows, manages contacts, can place and release holds. | 8 permissions |
treasury_admin | Configures treasury wallets and signers and runs the full transfer lifecycle. | 15 permissions |
treasury_signer | Drafts and approves treasury transfers and signs the on chain move. | 6 permissions |
treasury_viewer | Read only view of treasury wallets and activity. | 1 permissions |
tokenize_admin | Deploys tokens and manages the tokenization surface. | 18 permissions |
tokenize_minter | Mints from existing tokens. | 2 permissions |
Role grants
compliance_officer
policy.read policy.decision.read compliance_case.read compliance_case.flag compliance_case.transition compliance_case.assign compliance_case.update compliance_case.escalate compliance_case.comment compliance_case.sar_file compliance_case.close verification_policy.read verification_policy.update verification.holder.read verification.holder.approve verification.holder.reject account_holder.hold account_holder.release account_holder.offboard report.read audit.read governance.read approval_group.read approval_request.read
customer_service
payment.read escrow.read contact.read contact.write compliance_case.read compliance_case.flag account_holder.hold account_holder.release
treasury_admin
treasury.read treasury.create treasury.decommission treasury.signer.change treasury.threshold.change treasury.transfer.draft treasury.transfer.approve treasury.transfer.execute treasury.transfer.cancel treasury.counterparty.add treasury.counterparty.remove treasury.revenue.designate treasury.revenue.relink treasury.revenue.relink.sign treasury.tax.export
treasury_signer
treasury.read treasury.transfer.draft treasury.transfer.approve treasury.transfer.execute treasury.transfer.cancel treasury.revenue.relink.sign
treasury_viewer
treasury.read
tokenize_admin
token.read token.deploy token.mint token.burn token.recover token.role.change token.policy.set token.pause token.distribution.create token.distribution.execute token.authority.register schema.publish schema.rebind schema.bind rwa.field.commit rwa.corporate_action.create rwa.holder.eligibility.set rwa.attester.register
tokenize_minter
token.read token.mint
Permission catalog
129 permissions across 32 resources. Permissions marked platform are reserved for platform staff and are not grantable to tenant roles.
account_holder 3
account_holder.hold account_holder.offboard account_holder.release
api_key 6
api_key.create api_key.read api_key.revoke api_key.role_grant api_key.role_revoke api_key.rotate
approval 2
approval.attest approval.cancel
approval_group 6
approval_group.create approval_group.delete approval_group.member_removal approval_group.membership_change approval_group.read approval_group.update
approval_request 1
approval_request.read
audit 2
audit.export audit.read
branding 2
branding.email_domain.manage branding.manage
break_glass 2
break_glass.arm break_glass.read
compliance_case 9
compliance_case.assign compliance_case.close compliance_case.comment compliance_case.escalate compliance_case.flag compliance_case.read compliance_case.sar_file compliance_case.transition compliance_case.update
contact 2
contact.read contact.write
entitlement 1
entitlement.redeem
escrow 3
escrow.cancel escrow.create escrow.read
fee_schedule 3
fee_schedule.commit fee_schedule.create fee_schedule.read
gateway 6
gateway.activate gateway.conformance gateway.pin_cert gateway.read gateway.register gateway.repoint
governance 2
governance.read governance.requirement_change
partner 3
partner.create platform partner.read platform partner.update platform
payment 6
payment.cancel payment.confirm payment.create payment.force_cancel payment.read payment.send_lock
policy 4
policy.commit policy.create policy.decision.read policy.read
production_access 3
production_access.approve platform production_access.read platform production_access.request
ramp 2
ramp.offramp.create ramp.onramp.create
report 1
report.read
role 4
role.create role.delete role.read role.update
rwa 4
rwa.attester.register rwa.corporate_action.create rwa.field.commit rwa.holder.eligibility.set
schema 3
schema.bind schema.publish schema.rebind
staff 5
staff.invite staff.read staff.revoke staff.role_change staff.transfer_ownership
tenant 4
tenant.create tenant.delete tenant.onboard tenant.update
token 11
token.authority.register token.burn token.deploy token.distribution.create token.distribution.execute token.mint token.pause token.policy.set token.read token.recover token.role.change
treasury 15
treasury.counterparty.add treasury.counterparty.remove treasury.create treasury.decommission treasury.read treasury.revenue.designate treasury.revenue.relink treasury.revenue.relink.sign treasury.signer.change treasury.tax.export treasury.threshold.change treasury.transfer.approve treasury.transfer.cancel treasury.transfer.draft treasury.transfer.execute
verification 3
verification.holder.approve verification.holder.read verification.holder.reject
verification_policy 2
verification_policy.read verification_policy.update
webhook 7
webhook.create webhook.delete webhook.read webhook.replay webhook.rotate webhook.test webhook.update
workspace 2
workspace.read workspace.update