XKOVA Docs

Roles and Permissions

One permission registry governs every guarded action. This page lists the built in roles, what each one grants, and the full catalog of 129 permissions. It is generated from the registry, so it cannot drift.

XKOVA has one permission registry. Every guarded action checks a resource.action permission. Roles are named bundles of permissions. A tenant can also define custom roles from the same catalog.

Built in roles

RoleWhat it doesGrants
ownerFull control of the tenant. Holds every non platform permission.all non platform permissions
adminAdministers the tenant. Holds every non platform permission.all non platform permissions
compliance_officerReviews compliance cases, holds and releases account holders, reads the audit and approval trail.24 permissions
customer_serviceFront line support. Reads payments and escrows, manages contacts, can place and release holds.8 permissions
treasury_adminConfigures treasury wallets and signers and runs the full transfer lifecycle.15 permissions
treasury_signerDrafts and approves treasury transfers and signs the on chain move.6 permissions
treasury_viewerRead only view of treasury wallets and activity.1 permissions
tokenize_adminDeploys tokens and manages the tokenization surface.18 permissions
tokenize_minterMints from existing tokens.2 permissions

Role grants

compliance_officer

policy.read policy.decision.read compliance_case.read compliance_case.flag compliance_case.transition compliance_case.assign compliance_case.update compliance_case.escalate compliance_case.comment compliance_case.sar_file compliance_case.close verification_policy.read verification_policy.update verification.holder.read verification.holder.approve verification.holder.reject account_holder.hold account_holder.release account_holder.offboard report.read audit.read governance.read approval_group.read approval_request.read

customer_service

payment.read escrow.read contact.read contact.write compliance_case.read compliance_case.flag account_holder.hold account_holder.release

treasury_admin

treasury.read treasury.create treasury.decommission treasury.signer.change treasury.threshold.change treasury.transfer.draft treasury.transfer.approve treasury.transfer.execute treasury.transfer.cancel treasury.counterparty.add treasury.counterparty.remove treasury.revenue.designate treasury.revenue.relink treasury.revenue.relink.sign treasury.tax.export

treasury_signer

treasury.read treasury.transfer.draft treasury.transfer.approve treasury.transfer.execute treasury.transfer.cancel treasury.revenue.relink.sign

treasury_viewer

treasury.read

tokenize_admin

token.read token.deploy token.mint token.burn token.recover token.role.change token.policy.set token.pause token.distribution.create token.distribution.execute token.authority.register schema.publish schema.rebind schema.bind rwa.field.commit rwa.corporate_action.create rwa.holder.eligibility.set rwa.attester.register

tokenize_minter

token.read token.mint

Permission catalog

129 permissions across 32 resources. Permissions marked platform are reserved for platform staff and are not grantable to tenant roles.

account_holder 3

account_holder.hold account_holder.offboard account_holder.release

api_key 6

api_key.create api_key.read api_key.revoke api_key.role_grant api_key.role_revoke api_key.rotate

approval 2

approval.attest approval.cancel

approval_group 6

approval_group.create approval_group.delete approval_group.member_removal approval_group.membership_change approval_group.read approval_group.update

approval_request 1

approval_request.read

audit 2

audit.export audit.read

branding 2

branding.email_domain.manage branding.manage

break_glass 2

break_glass.arm break_glass.read

compliance_case 9

compliance_case.assign compliance_case.close compliance_case.comment compliance_case.escalate compliance_case.flag compliance_case.read compliance_case.sar_file compliance_case.transition compliance_case.update

contact 2

contact.read contact.write

entitlement 1

entitlement.redeem

escrow 3

escrow.cancel escrow.create escrow.read

fee_schedule 3

fee_schedule.commit fee_schedule.create fee_schedule.read

gateway 6

gateway.activate gateway.conformance gateway.pin_cert gateway.read gateway.register gateway.repoint

governance 2

governance.read governance.requirement_change

partner 3

partner.create platform partner.read platform partner.update platform

payment 6

payment.cancel payment.confirm payment.create payment.force_cancel payment.read payment.send_lock

policy 4

policy.commit policy.create policy.decision.read policy.read

production_access 3

production_access.approve platform production_access.read platform production_access.request

ramp 2

ramp.offramp.create ramp.onramp.create

report 1

report.read

role 4

role.create role.delete role.read role.update

rwa 4

rwa.attester.register rwa.corporate_action.create rwa.field.commit rwa.holder.eligibility.set

schema 3

schema.bind schema.publish schema.rebind

staff 5

staff.invite staff.read staff.revoke staff.role_change staff.transfer_ownership

tenant 4

tenant.create tenant.delete tenant.onboard tenant.update

token 11

token.authority.register token.burn token.deploy token.distribution.create token.distribution.execute token.mint token.pause token.policy.set token.read token.recover token.role.change

treasury 15

treasury.counterparty.add treasury.counterparty.remove treasury.create treasury.decommission treasury.read treasury.revenue.designate treasury.revenue.relink treasury.revenue.relink.sign treasury.signer.change treasury.tax.export treasury.threshold.change treasury.transfer.approve treasury.transfer.cancel treasury.transfer.draft treasury.transfer.execute

verification 3

verification.holder.approve verification.holder.read verification.holder.reject

verification_policy 2

verification_policy.read verification_policy.update

webhook 7

webhook.create webhook.delete webhook.read webhook.replay webhook.rotate webhook.test webhook.update

workspace 2

workspace.read workspace.update