Skip to main content

Roles and permissions

Access to the admin console is role-based. Operators only see and change what their roles allow.

Grants

  1. The person must already exist as a platform user (they have signed in at least once).
  2. A super-admin creates an admin grant for that user and assigns one or more roles.
  3. Effective permissions are the union of all assigned roles.
  4. Within a domain, Write includes Read.

Super-admin

The built-in super-admin role holds every permission and is the only role that can:

  • Create, edit, and revoke admin grants
  • Create custom roles
  • Assign roles to operators

The system always retains at least one super-admin (last super-admin safeguard).

Custom roles

Super-admins define named roles from the fixed domain catalog. Custom role permission sets are immutable after creation: to change access, create a new role and reassign operators. Unused roles can be archived (one-way).

Practical partner setups

TeamTypical access
SupportUsers read, chat moderation, limited funding read
FinanceEarnings / fee transactions, withdrawals history
GrowthQuests, mailing, marketing banners
RiskCopy-trading oversight, logs
Tech leadSuper-admin or infra + configuration

Exact role templates are configured during onboarding.