Roles & permissions
Roles
Every user has one of six tenant roles: Admin, Operator, Merchant, ISO, Syndicator, Referrer. Admins get every permission by default.
Permission flags
Fine-grained permission flags gate actions across the app - viewing and editing merchants/deals/funders/ISOs, managing payments, company settings, webhooks, API access, and more. These are enforced server-side on every API route, not just hidden in the UI.
Manage who-can-do-what under Users (assign roles) and permission profiles.
If a feature shows "You don’t have permission…", your profile is missing the relevant flag - ask an administrator. On the read-only demo, edit/admin actions are intentionally disabled.
Can’t find what you need? Return to the app or contact your administrator.