Permissions
A permission controls a single action on a single resource. A resource is an area or feature of the dashboard, such as API keys, payments, or transfers. Fintoc groups permissions into five categories: Payment initiation, Treasury, Reconciliation, Developers, and Administration.Access levels
Each resource grants one of four access levels. The levels are cumulative: Manage includes everything in Read.- None: No access to the resource.
- Read: See the resource’s information without making changes.
- Manage: Create, edit, and delete, in addition to everything in Read.
- Authorize: Approve or reject an action that another team member started. Only transfers use this level, through a maker/checker flow.
Roles
A role is a predefined bundle of permissions that matches a common job function. Assign a role to a user as a starting point, then adjust that user’s individual permissions when the role does not fit. Fintoc provides five predefined roles:- Admin: Every permission, including team management, billing, organization settings, and IP restrictions.
- Developer: Full access to API keys, webhooks, and JSON Web Signature (JWS) public keys, plus read-only access to payments and reconciliation.
- Operations: Manage links and refunds, plus read-only access to payments, payouts, and subscriptions.
- Finance and Accounting: Read-only access to payments, payouts, subscriptions, and reconciliation.
- Support: Read-only access to payments and subscriptions, plus the ability to refund payments.