Roles and permissions
Who can see and do what: the fifteen roles, the eight levels of access, and how an organisation narrows them.
How access is decided
Every screen and every action asks the same question before it runs: does this person’s role hold enough authority over this kind of record? The answer comes from a permission matrix — a grid of roles down one side and areas of the product along the other — and it is consulted again on every request. Nothing is decided once at sign-in and trusted afterwards.
That matters for two reasons an auditor will care about. Removing someone’s access takes effect on their next click rather than at their next sign-in. And a link copied out of one person’s browser and pasted into another’s does not carry their authority with it: the second person is asked the same question and gets their own answer.
The eight levels
Authority is graded rather than on-or-off. Each level includes everything below it, so a role that may approve may also read.
| Level | What it allows |
|---|---|
| None | No access. The area does not appear, and a direct link is refused. |
| Metadata | That a record exists, and little else — a document’s name and date without its contents. |
| Read | See the records, but change nothing. |
| Contribute | Add new records without altering what is already there. |
| Edit | Create and change records. |
| Review | Put work forward for approval, and send it back. |
| Approve | Sign off. This is the level that makes a figure official. |
| Administer | Configure the area itself, including who else may use it. |
The roles
Fifteen roles ship as defaults. The first eleven work inside the firm; the last four are outside it and see only their own records.
| Role | Who it is for |
|---|---|
| Platform admin | The operator of the platform itself. Scoped to the life cycle of an organisation, not to its contents. |
| Org admin | Configures the firm: users, roles, integrations, retention and white-label settings. |
| Fund manager | The general partner’s decision-maker. Approves capital activity and fund economics. |
| Fund controller | Reviews the numbers before they are approved, and owns the close. |
| Fund accountant | Prepares the work: entries, accruals, allocations, reconciliations. |
| Fund administrator | An outsourced administrator working inside the firm’s books, with the same preparation duties. |
| Investor relations | Owns the investor relationship: the register, communications and the portal, with read access to the numbers. |
| Tax advisor | Reads what tax work requires, limited to the funds they are engaged on. |
| Auditor | Reads what an audit requires, limited to the funds and periods they are engaged on. Changes nothing. |
| Legal counsel | Works the legal record — clauses, side letters, consents, transfers, holds — within their engagement. |
| LPAC member | A limited partner sitting on the advisory committee, who sees committee material alongside their own investor record. |
| Limited partner | Sees their own commitments, capital account, statements and documents. |
| LP signatory | The person at an investor who signs: subscriptions, consents, elections. |
| LP finance | The finance contact at an investor, who needs the numbers and the wire details but does not sign. |
| Portfolio company user | Someone at a portfolio company submitting their own reporting, who sees nothing of the fund. |
Narrowing a role for your firm
The defaults are a starting point, not a ceiling. An organisation can narrow what a role holds in a given area, and the narrowed answer is the one every screen and action uses from then on — including the navigation, so a person is not shown a door that will refuse them.
Narrowing is recorded per organisation. Another firm on the platform is unaffected, and the change is written to the audit trail like any other.
Where more than a role is required
Some decisions need more than authority. Three rules sit on top of the matrix and cannot be satisfied by a role alone.
- Separation of duties. Where work is reviewed and then approved, the same person cannot do both. The second signature has to be a different one.
- Engagement scope. An auditor, a tax advisor and legal counsel see only the funds and periods they are engaged on. The engagement is a record, not a setting on the person.
- Entitlement. An investor-side role is scoped to that investor. Holding the limited-partner role does not show you limited partners in general; it shows you the investor you are attached to.
Emergency access exists for the case where nobody who should be able to act is available. It is time-boxed, it announces itself, and everything done under it is marked as such in the audit trail. See Security and trust.