Access and control

You can control how users, external partners and integrated applications interact with the platform, and what actions they are permitted to perform, ensuring that only authorised users or APIs can view account data, instruct payments, and make configuration changes.

Access is managed through a combination of user roles or API scopes and account access. Users are assigned one or more roles, which define the actions they can perform. Integrated applications are granted API scopes, which define the operations they can perform. Users and integrated applications are also granted access to specific accounts, which determines the accounts they can view and operate on. You can apply additional controls, such as approval workflows, to govern sensitive actions.

You can extend access to external partners, such as TPAs or brokers, through delegated access. Organisations retain full control over delegated access, including the ability to grant or revoke access to shared accounts. User roles and API scopes continue to determine the actions that partner users and integrated applications can perform. This allows organisations to collaborate with partners while maintaining visibility and control over funds and payment activity.