Roles and Permissions
One permission registry governs every guarded action. This page lists the built in tenant roles, what each one grants, and the 134 permissions a tenant role may hold. It is generated from the registry, so it cannot drift.
resource.action permission. Roles are named bundles of permissions. A tenant can also define custom roles from the same catalog.Least-privilege API keys
In Console Team > Roles, define a custom role containing the exact operations an integration needs, then select it when creating an API key. For example, a payment and webhook integration can use payment.read, payment.create, webhook.read, webhook.create, and webhook.delete, with the payment and webhook resource scopes.
Scopes narrow role permissions; they never grant permissions alone. A key with wildcard scope and no roles cannot read payments, escrows, or account holders. Keys receive no implicit administrator authority. Only roles owned by the current tenant and delegable by the issuer can be assigned. If quorum approval is required, changing a custom role before application requires fresh approval.
Built in roles
| Role | What it does | Grants |
|---|---|---|
owner | Full control of the tenant. Holds every non platform permission. | all non platform permissions |
admin | Administers the tenant. Holds every non platform permission. | all non platform permissions |
compliance_officer | Reviews compliance cases, holds and releases account holders, reads the audit and approval trail. | 26 permissions |
customer_service | Front line support. Manages account-holder profiles and contacts, reads wallets, payments and escrows, and can place and release holds. | 12 permissions |
treasury_admin | Configures treasury wallets and signers and runs the full transfer lifecycle. | 15 permissions |
treasury_signer | Drafts and approves treasury transfers and signs the on chain move. | 6 permissions |
treasury_viewer | Read only view of treasury wallets and activity. | 1 permissions |
tokenize_admin | Deploys tokens and manages the tokenization surface. | 18 permissions |
tokenize_minter | Mints from existing tokens. | 2 permissions |
Role grants
compliance_officer
policy.read policy.decision.read compliance_case.read compliance_case.flag compliance_case.transition compliance_case.assign compliance_case.update compliance_case.escalate compliance_case.comment compliance_case.sar_file compliance_case.close verification_policy.read verification_policy.update verification.holder.read verification.holder.approve verification.holder.reject account_holder.read wallet.read account_holder.hold account_holder.release account_holder.offboard report.read audit.read governance.read approval_group.read approval_request.read
customer_service
account_holder.read account_holder.create account_holder.update wallet.read payment.read escrow.read contact.read contact.write compliance_case.read compliance_case.flag account_holder.hold account_holder.release
treasury_admin
treasury.read treasury.create treasury.decommission treasury.signer.change treasury.threshold.change treasury.transfer.draft treasury.transfer.approve treasury.transfer.execute treasury.transfer.cancel treasury.counterparty.add treasury.counterparty.remove treasury.revenue.designate treasury.revenue.relink treasury.revenue.relink.sign treasury.tax.export
treasury_signer
treasury.read treasury.transfer.draft treasury.transfer.approve treasury.transfer.execute treasury.transfer.cancel treasury.revenue.relink.sign
treasury_viewer
treasury.read
tokenize_admin
token.read token.deploy token.mint token.burn token.recover token.role.change token.policy.set token.pause token.distribution.create token.distribution.execute token.authority.register schema.publish schema.rebind schema.bind rwa.field.commit rwa.corporate_action.create rwa.holder.eligibility.set rwa.attester.register
tokenize_minter
token.read token.mint
Permission catalog
134 tenant-grantable permissions across 33 resources. Private platform-management permissions are intentionally omitted.
account_holder 6
account_holder.create account_holder.hold account_holder.offboard account_holder.read account_holder.release account_holder.update
api_key 6
api_key.create api_key.read api_key.revoke api_key.role_grant api_key.role_revoke api_key.rotate
approval 2
approval.attest approval.cancel
approval_group 6
approval_group.create approval_group.delete approval_group.member_removal approval_group.membership_change approval_group.read approval_group.update
approval_request 1
approval_request.read
audit 2
audit.export audit.read
billing 3
billing.portal.manage billing.read billing.subscription.manage
branding 2
branding.email_domain.manage branding.manage
break_glass 2
break_glass.arm break_glass.read
compliance_case 9
compliance_case.assign compliance_case.close compliance_case.comment compliance_case.escalate compliance_case.flag compliance_case.read compliance_case.sar_file compliance_case.transition compliance_case.update
contact 2
contact.read contact.write
entitlement 1
entitlement.redeem
escrow 3
escrow.cancel escrow.create escrow.read
fee_schedule 3
fee_schedule.commit fee_schedule.create fee_schedule.read
gateway 6
gateway.activate gateway.conformance gateway.pin_cert gateway.read gateway.register gateway.repoint
governance 2
governance.read governance.requirement_change
payment 6
payment.cancel payment.confirm payment.create payment.force_cancel payment.read payment.send_lock
policy 4
policy.commit policy.create policy.decision.read policy.read
production_access 1
production_access.request
ramp 2
ramp.offramp.create ramp.onramp.create
report 1
report.read
role 4
role.create role.delete role.read role.update
rwa 4
rwa.attester.register rwa.corporate_action.create rwa.field.commit rwa.holder.eligibility.set
schema 3
schema.bind schema.publish schema.rebind
staff 7
staff.federation.manage staff.federation.read staff.invite staff.read staff.revoke staff.role_change staff.transfer_ownership
tenant 4
tenant.create tenant.delete tenant.onboard tenant.update
token 11
token.authority.register token.burn token.deploy token.distribution.create token.distribution.execute token.mint token.pause token.policy.set token.read token.recover token.role.change
treasury 15
treasury.counterparty.add treasury.counterparty.remove treasury.create treasury.decommission treasury.read treasury.revenue.designate treasury.revenue.relink treasury.revenue.relink.sign treasury.signer.change treasury.tax.export treasury.threshold.change treasury.transfer.approve treasury.transfer.cancel treasury.transfer.draft treasury.transfer.execute
verification 3
verification.holder.approve verification.holder.read verification.holder.reject
verification_policy 2
verification_policy.read verification_policy.update
wallet 2
wallet.decommission wallet.read
webhook 7
webhook.create webhook.delete webhook.read webhook.replay webhook.rotate webhook.test webhook.update
workspace 2
workspace.read workspace.update