Roles and permissions
Access to the admin console is role-based. Operators only see and change what their roles allow.
Grants
- The person must already exist as a platform user (they have signed in at least once).
- A super-admin creates an admin grant for that user and assigns one or more roles.
- Effective permissions are the union of all assigned roles.
- Within a domain, Write includes Read.
Super-admin
The built-in super-admin role holds every permission and is the only role that can:
- Create, edit, and revoke admin grants
- Create custom roles
- Assign roles to operators
The system always retains at least one super-admin (last super-admin safeguard).
Custom roles
Super-admins define named roles from the fixed domain catalog. Custom role permission sets are immutable after creation: to change access, create a new role and reassign operators. Unused roles can be archived (one-way).
Practical partner setups
| Team | Typical access |
|---|---|
| Support | Users read, chat moderation, limited funding read |
| Finance | Earnings / fee transactions, withdrawals history |
| Growth | Quests, mailing, marketing banners |
| Risk | Copy-trading oversight, logs |
| Tech lead | Super-admin or infra + configuration |
Exact role templates are configured during onboarding.