← Back to appMCA Manager Helpmcamgr.com
Browse help topics

Roles & permissions

Roles

Every user has one of six tenant roles: Admin, Operator, Merchant, ISO, Syndicator, Referrer. The role decides which shell the person lands in (staff app or a portal) and which alerts reach them; what they may actually do comes from their permission profile.

Profiles

A profile is a named set of the 120 flags below, attached to a role. Admins get every flag; start new staff from the Operator profile and add flags as needed. Every flag is enforced on the server on every API route, not just hidden in the UI. Two flags deserve care: readOnly blocks every change regardless of the others, and accessOnlyToAssignedEntitiesGranted narrows a user to the deals and merchants assigned to them — switching on every flag turns it on too, which is usually not what an admin meant.

Manage users, teams and profiles under Users. If a screen says "You don’t have permission…", the profile is missing the flag named in the message.

Recommended starting profiles

  • Underwriter: view merchants/deals/submissions, edit deals, decision engine, documents, no payments.
  • Funding / servicing: Operator flags (payments, collections, plans), activate advances, no company settings.
  • Sales: leads, merchants, create advances, ISO list; accessOnlyToAssignedEntitiesGranted for a team split.
  • Finance: reports, accounting, payouts, 1099s, view everything, edit nothing else.
  • Read-only auditor: view flags plus readOnly.

All flags

API access (legacy)

Pre-2026-09 API keys used these; new keys carry per-resource scopes instead (Settings → API keys).

FlagGrants
adminApiAbleToAccessAppAdmin API can access app
adminApiAbleToAccessPartnerAppAdmin API can access partner app
adminApiAbleToAccessWebhooksAdmin API can access webhooks
adminApiAbleToAccessIsoFeedAdmin API can access ISO feed
adminApiAbleToAccessLenderToIsoFeedAdmin API can access lender to ISO feed
adminApiAbleToAccessSyndicatorFeedAdmin API can access syndicator feed
adminApiAbleToAccessLenderFeedAdmin API can access lender feed
adminApiAbleToAccessLeadApiAdmin API can access lead API

Admin

Company-wide configuration, users, money corrections. Give these only to the people who run the desk.

FlagGrants
adminAbleToAddPaymentsAdmin can add payments
adminAbleToEditPaymentsAdmin can edit payments
adminAbleToEditMerchantUserAnnouncementsAdmin can edit merchant user announcements
adminDefaultMerchantViewTabSubmissionAdmin default merchant view tab submission
adminAbleToCreateAndDeleteStipsAdmin can create and delete stips
adminAbleToAddDocumentsToPendingStipsAdmin can add documents to pending stips
adminAbleToChangeStipStatusToUnderReviewAdmin can change stip status to under review
adminAbleToChangeStipStatusToCompletedAdmin can change stip status to completed
adminAbleToChangeStipStatusToWaivedAdmin can change stip status to waived
adminAbleToAccessContactCenterAdmin can access contact center
adminAbleToCreateNewDocumentTypesAdmin can create new document types
adminAbleToDiscardTasksAdmin can discard tasks
adminAbleToAccessLocMerchantPortalAdmin can access loc merchant portal
adminAbleToAccessOmMerchantPortalAdmin can access om merchant portal
adminAbleToEditTagsAdmin can edit tags
adminAbleToMergeMerchantsAdmin can merge merchants

Operator

Day-to-day servicing: payments, collections, notes.

FlagGrants
operatorAbleToEditMerchantUserAnnouncementsOperator can edit merchant user announcements
operatorDefaultMerchantViewTabSubmissionOperator default merchant view tab submission
operatorAbleToCreateAndDeleteStipsOperator can create and delete stips
operatorAbleToAddDocumentsToPendingStipsOperator can add documents to pending stips
operatorAbleToChangeStipStatusToUnderReviewOperator can change stip status to under review
operatorAbleToChangeStipStatusToCompletedOperator can change stip status to completed
operatorAbleToChangeStipStatusToWaivedOperator can change stip status to waived
operatorAbleToAccessContactCenterOperator can access contact center
operatorAbleToDiscardTasksOperator can discard tasks
operatorAbleToAccessLocMerchantPortalOperator can access loc merchant portal
operatorAbleToAccessOmMerchantPortalOperator can access om merchant portal
operatorAbleToCreateNewDocumentTypesOperator can create new document types
operatorAbleToViewPaymentsOperator can view payments
operatorAbleToViewBouncedPaymentsOperator can view bounced payments
operatorAbleToEditTagsOperator can edit tags
operatorAdvanceViewActionsRestrictionsOperator advance view actions restrictions
operatorAbleToAddPaymentsOperator can add payments
operatorAbleToEditPaymentsOperator can edit payments
operatorAbleToMergeMerchantsOperator can merge merchants

ISO portal

What a broker sees and may do in their portal.

FlagGrants
isoAbleToViewPaymentsISO can view payments

Referrer portal

Referral partners: their leads and payouts only.

FlagGrants
referrerAbleToViewDashboardReferrer can view dashboard
referrerAbleToViewPaymentsReferrer can view payments

Lead visibility

Restrictions on which leads a user can see.

FlagGrants
leadRestrictionViewListLead restriction view list
leadRestrictionViewItemLead restriction view item
leadRestrictionEditItemLead restriction edit item

Working the book

Viewing and editing merchants, deals, funders, ISOs, submissions, documents, reports, settings.

FlagGrants
readOnlyRead-only (blocks all changes)
ableToEditCompanySettingsCan edit company settings
ableToViewUsersAndTeamsCan view users and teams
ableToEditUsersPermissionsCan edit users permissions
ableToEditAdvancesCan edit advances
ableToAccessSyndicatorProfitForecastCan access syndicator profit forecast
ableToAccessCompanyProfitForecastCan access company profit forecast
ableToEditPipelinesCan edit pipelines
ableToEditCreditPolicyCan edit credit policy
ableToEditCompanyStipsCan edit company stips
ableToModifyIsosAndLendersCan modify isos and lenders
ableToEditIsoAndLenderBankAccountsCan edit ISO and lender bank accounts
ableToAccessIsoListCan access ISO list
ableToAccessIsoCan access ISO
ableToAccessLenderListCan access lender list
ableToViewIsoCan view ISO
ableToViewLenderCan view lender
ableToSearchMerchantAndIsoContactsCan search merchant and ISO contacts
ableToCreateMerchantUsersCan create merchant users
ableToAssignEntitiesCan assign entities
ableToViewEntityIdCan view entity ID
accessOnlyToAssignedEntitiesGrantedAccess only to assigned entities granted
accessToEmailsGrantedAccess to emails granted
ableToDeleteAdvanceSubmissionsCan delete advance submissions
ableToCreatePublicSavedReportsCan create public saved reports
ableToViewAdvancesCan view advances
ableToViewMerchantsCan view merchants
ableToCreateAdvancesCan create advances
ableToEditAdvanceParticipationCan edit advance participation
ableToEditSubmissionsCan edit submissions
ableToDownloadDocumentsCan download documents
ableToDownloadLettersCan download letters
ableToEditActiveAdvancesCan edit active advances
ableToViewCommissionsAndFeesCan view commissions and fees
ableToManageAchOriginationCan manage ACH origination
ableToManageApplicationFormsCan manage application forms
ableToRunPayoutsCan run payouts
ableToManageTaxFormsCan manage tax forms
ableToManageFunderProfilesCan manage funder profiles
ableToRunSanctionsScreeningCan run sanctions screening
ableToAdjudicateSanctionsCan adjudicate sanctions
ableToAccessBulkActionsCan access bulk actions
ableToSubmitApplicationsCan submit applications
ableToActivateAdvancesCan activate advances
ableToBulkUploadMerchantsCan bulk upload merchants
ableToDeleteMerchantBulkUploadActivitiesCan delete merchant bulk upload activities
ableToDeleteOnlyOwnMerchantBulkUploadActivitiesCan delete only own merchant bulk upload activities
ableToImportMigrationDataCan import migration data
ableToViewCreditPolicyCan view credit policy
ableToAccessDashboardCan access dashboard
ableToAccessProfitForecastCan access profit forecast
ableToAccessLedgerCan access ledger
ableToAccessAccountingCan access accounting
ableToViewDashboardCan view dashboard
ableToCreateLeadsCan create leads
ableToViewLeadsCan view leads
ableToViewAllLeadsCan view all leads
ableToEditAllLeadsCan edit all leads
ableToRequestAdditionalFundsCan request additional funds
ableToRequestPayoffLetterCan request payoff letter
ableToRequestBalanceLetterCan request balance letter
ableToUploadAndDownloadDocumentsCan upload and download documents
ableToAccessContactCenterCan access contact center
ableToAccessLocMerchantPortalCan access loc merchant portal
ableToAccessOmMerchantPortalCan access om merchant portal
ableToChangeDoNotDisturbCan change do not disturb
powerBiReportingEnabledPower BI reporting enabled
ableToExportPowerBiReportsCan export power BI reports
ableToSendForSignatureCan send for signature
ableToManageSignatureTemplatesCan manage signature templates
ableToVoidSignatureRequestsCan void signature requests

Can’t find what you need? Return to the app or contact your administrator.

Roles & permissions - Help