Roles & Permissions
Access to the platform is governed by four roles. Three are for people using the dashboard; one is for system-to-system integration. Permissions are enforced by the platform (not only hidden in the UI) and are scoped per tenant.
The roles
| Role | For | Summary |
|---|---|---|
| Operator | Front-line reviewers | Day-to-day case work: view records, work the review queue, Accept/Reject, resolve duplicates. |
| Supervisor | Team leads | Everything an Operator can, plus data corrections, decision reversals, blocklisting, and anonymization; selected settings. |
| Administrator | Tenant admins | Configuration and user management. Typically not involved in individual cases. |
| System | Integrations | The Company's backend calling the APIs (OAuth2). Not a person and not a dashboard login. |
Responsibility matrix
| Capability | Operator | Supervisor | Administrator |
|---|---|---|---|
| View Digital Identities & Customers | ✅ | ✅ | ✅ |
| Accept / Reject a review | ✅ | ✅ | — |
| Resolve duplicates (Unique / Merge) | ✅ | ✅ | — |
| Edit Customer personal data | — | ✅ | — |
| Reset a decision to Review | — | ✅ | — |
| Put on Blocklist | — | ✅ | — |
| Anonymize (GDPR erasure) | — | ✅ | — |
| Configure Trust Factors, documents, duplicity check | — | — | ✅ |
| Author / publish workflows | — | ✅ | ✅ |
| Manage users & roles | — | — | ✅ |
| Configure integrations & webhooks | — | — | ✅ |
Administrator involvement in some case-level actions may be granted per deployment; the table shows the default split. Every action — human or system — is audited.