Permissions Catalogue
Permissions are pre-defined within the Fenergo SaaS application and represent a series of functional capabilities across the various features within the application.
Permissions determine what a user can do within the system. They cover administrative, operational and configuration based user activities.
From an Operational user's POV, permissions control what the user can access, create, cancel, etc. For example, a user may have permission to initiate journey, access client entity data, and trigger screening. Permissions also govern what the Configuration user is allowed to do within the system whether including operations such as create, edit, and approve with respect to configuration sets. For example, a user may have permission to create Policy drafts, edit the requirements within it, and then approve any changes to policies.
Permissions are organized by Domain and are pre-defined per specific API capabilities within the system. Permissions are broken up into the following categories:
- Access - the ability to access a feature
- Edit - the ability to edit within a feature
- Create - the ability to create an instance of an object related to feature
- Cancel - the ability to cancel an activity within a feature
- Delete - the ability to delete within a feature
- Approve - the ability to approve within a feature
- Archive - the ability to archive within a feature
Permissions are added to Teams. While the individual permissions are pre-configured and cannot be changed, Teams are configurable and the the combinations of permissions contained within team are fully configurable.
This document also includes information on configuration permissions that are pre-defined within the system, but are typically only provisioned to System Configuration or Application Support Teams.
Refer to the Access Management User Guide for more details on how Permissions are used within Fenergo SaaS
Current Permissions
Access Management
User Management
| Permission Name | Description | Scope Reference |
|---|---|---|
| Security User Administration | Access the User Administration feature to manage user accounts. | UserAdministration |
| Security Create New User | Create new user accounts. | SecurityCreateUser |
| Security Edit Users | Edit existing user accounts. | SecurityEditUser |
| Security Remove Users | Delete user accounts. | SecurityDeleteUser |
Team & Access Layer Management
| Permission Name | Description | Scope Reference |
|---|---|---|
| Security Configuration Access | Access the Security Configuration feature, where teams and permissions are managed. | SecurityConfigAccess |
| Security Configuration Create | Create new teams and assign permissions to them. | SecurityConfigCreate |
| Security Configuration Edit | Edit existing teams, including the permissions assigned to them. | SecurityConfigEdit |
| Security Configuration Delete | Delete teams. | SecurityConfigDelete |
| Landing Page Edit | Set the field 'Default landing page for team members when logging in'. | LandingPageEdit |
Client Management
| Permission Name | Description | Scope Reference |
|---|---|---|
| Security Client Administration | View clients via Client Management. | ClientAdministration |
| Security Client Secret Administration | Access client secrets via Secret Management - actual secret values are only visible on initial generation. | SecretAdministration |
| Security Create New Client | Create new clients. | SecurityCreateClient |
| Security Create New Client Secret | Create new client secrets. | SecurityCreateSecret |
| Security Edit Clients | Edit client. | SecurityEditClient |
| Security Remove Client Secrets | Remove client secrets. | SecurityDeleteSecret |
| Security Remove Clients | Remove client. | SecurityDeleteClient |
External Authentication
| Permission Name | Description | Scope Reference |
|---|---|---|
| External Authentication Configuration Access | Access existing External Authentication Configuration via query API. | ExternalAuthenticationAccess |
| External Authentication Configuration Create | Create new External Authentication Configuration via command API. This supports mTLS (Mutual Transport Layer Security) and OAuth 2.0 Client Credentials on outbound traffic originating from the following services Webhooks, External Data Adapters and Screening Adapters. | ExternalAuthenticationCreate |
| External Authentication Configuration Edit | Edit existing External Authentication Configuration via command API. | ExternalAuthenticationEdit |
| External Authentication Configuration Delete | Delete existing External Authentication Configuration via command API. | ExternalAuthenticationDelete |
Audit
| Permission Name | Description | Scope Reference |
|---|---|---|
| Audit Access & Search | Access and search the system audit log, providing visibility of the system audit trail, including the audit history of individual entities and their journeys. | AuditAccessAndSearch |
Bulk Upload and Request
Bulk Request
| Permission Name | Description | Scope Reference |
|---|---|---|
| Bulk Request Access | Access the Bulk Request feature to submit and monitor bulk operations to update entity data. | BulkLoadAccess |
Change Management
Conflict Resolution
| Permission Name | Description | Scope Reference |
|---|---|---|
| Conflict Resolution Access | Access conflict resolution records within a journey. | ConflictResolutionAccess |
| Conflict Resolution Edit | Edit conflict resolution records within a journey. | ConflictResolutionEdit |
Proposed Changes
| Permission Name | Description | Scope Reference |
|---|---|---|
| Proposed Changes Access | Access and view Proposed Changes within a journey. | ProposedChangesAccess |
| Proposed Changes Edit | Action Proposed Changes by accepting or rejecting them within a journey. | ProposedChangesEdit |
Review and Approval
| Permission Name | Description | Scope Reference |
|---|---|---|
| Review & Approval Access | Access the Review & Approval task. | ReviewApprovalAccess |
| Review & Approval Comment | Leave comments on desired data points that require attention. | ReviewApprovalComment |
| Review & Approval Configuration Access | Access Review & Approval Configuration. | ReviewApprovalConfigurationAccess |
| Review & Approval Configuration Create | Create Review & Approval Configuration. | ReviewApprovalConfigurationCreate |
| Review & Approval Configuration Edit | Edit Review & Approval Configuration. | ReviewApprovalConfigurationEdit |
| Review & Approval Configuration Approve | Approve Review & Approval Configuration. | ReviewApprovalConfigurationApprove |
| Review & Approval Configuration Archive | Archive Review & Approval Configuration. | ReviewApprovalConfigurationArchive |
| Review & Approval Configuration Delete | Delete Review & Approval Configuration. | ReviewApprovalConfigurationDelete |
| Review & Approval Decision | Make a decision on the Review & Approval task. | ReviewApprovalDecision |
| Review & Approval Resolve Comments | Resolve comments across the Review & Approval task. | ReviewApprovalResolveComments |
Comments
| Permission Name | Description | Scope Reference |
|---|---|---|
| Access to Comments | Access the comments drawer to view Comments and @mentions on an Entity Profile or within a Journey. | CommentsAccess |
| Create a Comment Thread | Create a comment thread. | CommentsCreate |
| Delete Any Comment | Delete any comment. | CommentsDeleteAny |
| Delete Your Own Comments | Delete your own comments. | CommentsDeleteOwn |
| Reply to a Comment Thread | Reply to a comment thread. | CommentsReply |
Configuration Baseline
| Permission Name | Description | Scope Reference |
|---|---|---|
| Configuration Baseline Access | Access configuration baseline records via API. | ConfigBaselineAccess |
| Configuration Baseline Edit | Edit configuration baseline models via API. | ConfigBaselineEdit |
Configuration Exchange
| Permission Name | Description | Scope Reference |
|---|---|---|
| Configuration Exchange Access | Access configuration exchange import records. | ConfigurationExchangeAccess |
| Configuration Exchange Edit | Create an import record and select configuration to import from a source tenant this target tenant. | ConfigurationExchangeEdit |
| Configuration Exchange Publish | Enables the option to Publish configuration on Import (vs importing versioned configuration in a draft state). | ConfigurationExchangePublish |
Dashboards and Reporting
Reporting
| Permission Name | Description | Scope Reference |
|---|---|---|
| Reporting Access | Access to Advanced Reporting and Legacy Reporting. In Advanced Reporting, view saved queries and their SQL; in Legacy Reporting, run the out-of-the-box reports. | ReportingAccess |
| Reporting Edit | Create, edit, preview and save Advanced Reporting queries. | ReportingEdit |
| Reporting Delete | Delete saved Advanced Reporting queries. | ReportingDelete |
| Reporting Execute | Run Advanced Reporting queries and download generated reports. | ReportingExecute |
| Reporting Admin | Access to Reporting Configurations, such as to configure branding for generated reports. | ReportingAdmin |
Advanced Dashboards
| Permission Name | Description | Scope Reference |
|---|---|---|
| Advanced Dashboard Configuration Edit | Edit configuration for Advanced Dashboards. | AdvancedDashboardConfigurationEdit |
| Advanced Dashboards Access | Access Advanced Dashboards. | AdvancedDashboardAccess |
| Bulk Actions on Tasks Dashboard | Bulk complete tasks as well as update Entity Data for those selected Tasks' on the Tasks Dashboard. | TaskBulkCompletion |
Dashboards
| Permission Name | Description | Scope Reference |
|---|---|---|
| Task Dashboard Access | Access task dashboard. | TaskDashboardAccess |
| Team Management Dashboard Access | Access team dashboard. | TeamDashboardAccess |
Business Metrics
| Permission Name | Description | Scope Reference |
|---|---|---|
| Business Metrics Access | Access Business Metrics. | BusinessMetricsAccess |
| Business Metrics Edit | Edit Business Metrics. | BusinessMetricsEdit |
Command Centre
| Permission Name | Description | Scope Reference |
|---|---|---|
| Command Centre Access | Access Command Centre. | CommandCentreAccess |
Data Migration
| Permission Name | Description | Scope Reference |
|---|---|---|
| Data Migration Administrator | Perform data migrations using the legacy capability (broadly replaced by ETL). | DataMigrationAdministrator |
Data Protection
Dashboards
| Permission Name | Description | Scope Reference |
|---|---|---|
| Data Protection Dashboard Access | Access Data Protection dashboard, where actioned or matched Orphan entities will be displayed. | DataProtectionDashboardAccess |
Configuration
| Permission Name | Description | Scope Reference |
|---|---|---|
| Data Protection Configuration Access | Access Data Protection Configuration, such as Data Protection Regimes and the Entity Check rule. | DataProtectionAccess |
| Data Protection Configuration Create | Create Data Protection Regimes, feature toggles and Entity Check rule configuration. | DataProtectionCreate |
| Data Protection Configuration Edit | Edit Data Protection Configuration. | DataProtectionEdit |
| Data Protection Configuration Approve | Approve Data Protection Configuration. | DataProtectionApprove |
| Data Protection Configuration Archive | Archive Data Protection Configuration. | DataProtectionArchive |
| Data Protection Configuration Delete | Delete Data Protection Configuration. | DataProtectionDelete |
| Data Protection Automatic Re-Onboarding Edit | Update Automatic Re-Onboarding toggle. | DataProtectionAutomaticReOnboardingEdit |
Legal Holds
| Permission Name | Description | Scope Reference |
|---|---|---|
| Legal Hold Access | View Legal Hold details and status on an Entity Profile and receive Legal Hold expiry notifications when eligible. | LegalHoldAccess |
| Legal Hold Edit | Create and modify a Legal Hold on an entity, including its reason, details, duration and Responsible Team. | LegalHoldEdit |
| Legal Hold Delete | Remove an existing Legal Hold from an entity, allowing the entity to return to the standard deletion lifecycle. | LegalHoldDelete |
Digital Agents
Central Agent Configuration
| Permission Name | Description | Scope Reference |
|---|---|---|
| Kyra Access | See and interact with Kyra. | KyraAccess |
| Agent Configuration Access | Access Agent configuration. | AgentConfigurationAccess |
| Agent Configuration Edit | Edit Agent configuration. | AgentConfigurationEdit |
| Agent Governance Access | Access digital agent metrics in the command centre, and agent rationale on the journey hub. | DigitalAgentsAccess |
Significance Rules
| Permission Name | Description | Scope Reference |
|---|---|---|
| Significance Task Access | Access, edit and complete the Significance Tasks. | SignificanceTaskAccess |
| Significance Task Edit | Overwrite task-level significance outcomes and complete the Significance Task. | SignificanceTaskEdit |
| Significance Rule Access | Access the Significance Rules. | SignificanceRuleAccess |
| Significance Rule Edit | Add and edit existing configuration. | SignificanceRuleEdit |
| Significance Rule Delete | Delete existing configuration. | SignificanceRuleDelete |
Policy Agent
| Permission Name | Description | Scope Reference |
|---|---|---|
| Policy Agent Access | Access Policy Agent. | PolicyAgentAccess |
| Policy Agent Edit | Edit Policy Agent. | PolicyAgentEdit |
| Policy Agent Approve | Approve Policy Agent changes. | PolicyAgentApprove |
| Policy Agent Delete | Delete Policy Agent activities. | PolicyAgentDelete |
Document Agent
| Permission Name | Description | Scope Reference |
|---|---|---|
| Document Agent Managed Knowledge Base Access | Access the Managed Knowledge Base used by the Document Agent. | IdpRagAccess |
| Document Agent Managed Knowledge Base Edit | Add new Knowledge Base entries or edit existing ones. | IdpRagEdit |
| Document Agent Managed Knowledge Base Delete | Delete existing resource. | IdpRagDelete |
Digital ID&V
| Permission Name | Description | Scope Reference |
|---|---|---|
| Digital ID&V Access | Provides access to Digital ID&V functionality and verification information within Fenergo SaaS. This includes viewing Digital ID&V information associated with individuals and accessing ID&V results presented for review as part of the Digital ID&V process. | DigitalIdvAccess |
| Digital ID&V Create | Allows users to initiate a Digital ID&V request through Jumio by generating a unique Jumio verification link for an individual. The link can be provided to the individual to complete the identity verification process, with the resulting status tracked in Fenergo SaaS | DigitalIdvCreate |
| Digital ID&V Configuration | Allows users to configure Digital ID&V within Fenergo SaaS, including creating and managing Identity Verification Configurations for the Fenergo SaaS Digital ID&V solution, as well as connecting, configuring, and enabling or disabling supported external Digital ID&V providers | DigitalIdvConfiguration |
| Digital ID&V Approve Or Reject | Allows users to approve or reject completed Digital ID&V results during the ID&V review process. Users can select the applicable approval or rejection reason and capture a supporting comment where required | ApproveOrReject |
ID&V
| Permission Name | Description | Scope Reference |
|---|---|---|
| ID&V Access | Allows a user to access the Related Party Data & Documents task in order to complete the additional data and document capture that forms ID&V. | IdvAccess |
| ID&V Edit | Allows a user to edit the fields within the Related Party Data & Documents task to complete the in-scope requirements. | IdvEdit |
| ID&V Delete | Ability to bring an entity out of scope for ID&V in a journey. | IdvDelete |
| ID&V Add Scope | Allows a user access to the grid option to add an associated Related Party to the scope of the task. | IdvAddScope |
| ID&V Remove Scope | Allows a user access to the grid option to remove one or more selected related parties from the scope of the task. This does not remove the entity from the hierarchy and does not delete the entity draft should any changes have been made. | IdvRemoveScope |
| ID&V Configuration Access | Allows a user to interact with and navigate into the Related Party Scoping Rules option under the Management Menu for Journey. Note: Journey Access is required to see this menu option. | IdvConfigurationAccess |
| ID&V Configuration Create | Allows a user to create a Related Party Scoping Rule or clone an existing Related Party Scoping Rule set. | IdvConfigurationCreate |
| ID&V Configuration Edit | Allows a user to create a new version of an existing Related Party Scoping Rule set, update an existing draft version of a Related Party Scoping Rule set, or submit an existing Related Party Scoping Rule set draft version for approval. | IdvConfigurationEdit |
| ID&V Configuration Approve | Allows a user to approve or reject a version of a Related Party Scoping Rule set which has been submitted for approval. | IdvConfigurationApprove |
| ID&V Configuration Archive | Allows a user to archive a version of a Related Party Scoping Rule set. | IdvConfigurationArchive |
| ID&V Configuration Delete | Allows a user to delete an existing Related Party Scoping Rule set and all its versions and delete the selected version of an existing Related Party Scoping Rule set. | IdvConfigurationDelete |
Document Management
| Permission Name | Description | Scope Reference |
|---|---|---|
| Document Management Access | View documents associated with an entity. Required by all users who need to open the Documents tab for an entity, view document metadata, and use the document viewer. | DocumentManagementAccess |
| Document Management Create | Upload new documents, populate document metadata, and submit requirements for approval, waive or deferral. Required by users who add documents to an entity. | DocumentManagementCreate |
| Document Management Create Virtual | Create virtual document management models. | DocumentManagementCreateVirtual |
| Document Management Edit | Edit the metadata of an existing document. | DocumentManagementEdit |
| Document Management Approve | Approve or reject document requirements. Allows approval of requirements with a status of Pending Approval, and rejection of requirements marked Waive Requested or Deferral Requested. | DocumentManagementApprove |
| Document Management - Archive | Archive documents on the entity profile page. Displays the archive control on the Documents tab. Unarchiving requires the separate Document Management - Unarchive permission. | DocumentManagementArchiveV2 |
| Document Management - Unarchive | Unarchive documents on the entity profile page. Archiving requires the separate Document Management - Archive permission. | DocumentManagementUnarchive |
| Document Management Delete | Delete a document that has previously been uploaded. | DocumentManagementDelete |
| Document Management Apply To All | Bulk actions applied to multiple selected Documents. | DocumentManagementApplyToAll |
| Document Management Defer or Waive | Approve document requirements with a status of Waive Requested or Deferral Requested. Note that rejecting requirements in these states additionally requires Document Management Approve. | DocumentManagementDeferOrWaive |
| Document Management Link | Link or reuse an existing document against a requirement without needing document create permissions. | DocumentManagementLink |
| Document Management Send for Signature | Request eSignature for a document requirement. Should not be granted where eSignature is not enabled for the tenant. | DocumentManagementSendForSignature |
Document Types and Metadata Configuration
| Permission Name | Description | Scope Reference |
|---|---|---|
| Document Configuration Access | Access and view Document Types and Document Requirement Metadata configuration under Reference Data. | DocumentConfigurationAccess |
| Document Configuration Edit | Create and update Document Type and Document Requirement Metadata configuration sets and their draft versions. | DocumentConfigurationEdit |
| Document Configuration Approve | Approve or reject Document Type and Document Requirement Metadata configuration versions submitted for approval. | DocumentConfigurationApprove |
| Document Configuration Archive | Archive a version of a Document Type or Document Requirement Metadata configuration set. | DocumentConfigurationArchive |
| Document Configuration Delete | Delete versions of Document Type or Document Requirement Metadata configuration sets. | DocumentConfigurationDelete |
Document Generation
| Permission Name | Description | Scope Reference |
|---|---|---|
| Document Generation Configuration Access | Access and view Document Generation configuration, including naming conventions, the Component Library and document templates. | DocGenConfigurationAccess |
| Document Generation Configuration Create | Create new Document Generation configuration sets, including naming conventions, component libraries and document templates. | DocGenConfigurationCreate |
| Document Generation Configuration Edit | Create new draft versions and modify Document Generation configuration, including components, mappings and templates, and submit versions for approval. | DocGenConfigurationEdit |
| Document Generation Configuration Approve | Approve or reject Document Generation configuration versions submitted for approval. | DocGenConfigurationApprove |
| Document Generation Configuration Archive | Archive a Document Generation configuration version. | DocGenConfigurationArchive |
| Document Generation Configuration Delete | Delete Document Generation configuration sets and their versions. | DocGenConfigurationDelete |
eSignature
| Permission Name | Description | Scope Reference |
|---|---|---|
| eSignature Configurator Access | Access and view eSignature provider configuration, including connection and signature settings. | ESignatureConfigurationAccess |
| eSignature Configurator Create | Create eSignature configuration. | ESignatureConfigurationCreate |
| eSignature Configurator Edit | Edit eSignature configuration. | ESignatureConfigurationEdit |
| eSignature Configurator Delete | Delete eSignature configuration. | ESignatureConfigurationDelete |
Entity Data
| Permission Name | Description | Scope Reference |
|---|---|---|
| Change Entity Draft Access Layers | Change the Access Layers assigned to an entity draft; changes are propagated to the related entity. | EntityDataChangeEntityDraftAccessLayers |
| Entity Data Access & Search | Search for and access entity and entity draft records, subject to the user's Access Layers. Baseline permission for users who need to find and open entity records. | EntityDataAccessAndSearch |
| Entity Data Edit | Create and update entity draft records, including entity data maintained through Journey tasks or supported APIs. | EntityDataEdit |
| Entity Data Approve | Verify or reject entity drafts, allowing approved draft changes to become verified entity data. Required for users responsible for approving entity data changes. | EntityDataApprove |
Entity Profile
| Permission Name | Description | Scope Reference |
|---|---|---|
| Entity Profile Export | Export information from the Entity Profile for printing or saving as PDF, including entity data, Journeys, Related Parties, Products, Documents, Policies and Access Layers. | EntityProfileExport |
| Entity Profile Configuration Access | Access and view Legal Entity Profile Configuration, including configuration defined for each Legal Entity Type and common profile settings. | EntityProfileConfigurationAccess |
| Entity Profile Configuration Edit | Modify Legal Entity Profile Configuration, including the Overview details category, visibility and ordering of Policy Categories, hidden statuses and common profile settings. | EntityProfileConfigurationEdit |
New Entity Flow
| Permission Name | Description | Scope Reference |
|---|---|---|
| New Entity Configuration Access | Access the configuration that guides the flow when a new entity is created. | NewEntityConfigurationAccess |
| New Entity Configuration Edit | Edit the configuration that guides the flow when a new entity is created. | NewEntityConfigurationEdit |
Entity Group Management
| Permission Name | Description | Scope Reference |
|---|---|---|
| Entity Group Management Access & Search | Search and access entity group records. Required by users who need to view Legal Entity Group records. | EntityGroupManagementAccessAndSearch |
| Shared Data Template Access | Access the Shared Data Template configuration area. Required before any other Shared Data Template permissions can be used. | SharedDataTemplateAccess |
| Entity Group Management Edit | Create and edit entity group records. Required by users responsible for maintaining Legal Entity Groups. | EntityGroupManagementEdit |
| Shared Data Template Create | Create new draft versions of Shared Data Templates that define the data, documents and Related Parties that can be shared within Legal Entity Groups. | SharedDataTemplateCreate |
| Shared Data Template Edit | Modify existing draft versions of Shared Data Templates. | SharedDataTemplateEdit |
| Shared Data Template Approve | Approve draft Shared Data Template versions for publication and use within Legal Entity Groups. | SharedDataTemplateApprove |
| Shared Data Template Archive | Archive published versions of Shared Data Templates. | SharedDataTemplateArchive |
| Shared Data Template Delete | Delete draft versions of Shared Data Templates. | SharedDataTemplateDelete |
ETL (Extract, Transform, Load)
ETL
| Permission Name | Description | Scope Reference |
|---|---|---|
| ETL administrator | Access the ETL feature to configure and manage extract, transform and load operations. | ETLAdministrator |
Agency Migration
| Permission Name | Description | Scope Reference |
|---|---|---|
| ETL Agency Migration Administrator | Access ETL Agency Migration projects to manage the migration of Agency objects (IM, UP, MR, Managed Products). | AgencyMigrationETLAdministrator |
Agency Bulk Upload
| Permission Name | Description | Scope Reference |
|---|---|---|
| Agency Request ETL administrator | Access and complete Agency ETL tasks to bulk upload UP, MR and Product data within an Agency Request journey. | AgencyETLAdministrator |
Events
Event Ingress
| Permission Name | Description | Scope Reference |
|---|---|---|
| Get Event Details | Get details of specific ingress event. | EventIngressGetEventDetails |
| Get Event Payload | Get payload of specific ingress event. | EventIngressGetEventPayload |
Event Notifications
| Permission Name | Description | Scope Reference |
|---|---|---|
| Webhook Access | Access webhook configuration. | WebhookAccess |
| Webhook Management | Create/edit/delete webhook configurations. | WebhookManagement |
External Data Sources
| Permission Name | Description | Scope Reference |
|---|---|---|
| External Data Access | Access External Data functionality within a Journey and initiate External Data searches against configured providers. | ExternalDataAccess |
| External Data Approve | Approve the import of new Related Parties through External Data-related review activities. | ExternalDataApprove |
| External Data Configurator Access | Access and view External Data provider configuration. | ExternalDataConfiguratorAccess |
| External Data Configurator Create | Create and configure new custom External Data providers. | ExternalDataConfiguratorCreate |
| External Data Configurator Edit | Modify existing External Data provider configuration. | ExternalDataConfiguratorEdit |
| External Data Configurator Delete | Delete a custom External Data provider and its configuration. | ExternalDataConfiguratorDelete |
| External Data Mapper Access | Access and view mappings between External Data providers and Fenergo Policy. | ExternalDataMapperAccess |
| External Data Mapper Edit | Create, modify and delete mappings between External Data provider data and Fenergo Policy. | ExternalDataMapperEdit |
Fenergo Portal
| Permission Name | Description | Scope Reference |
|---|---|---|
| Portal Administration User Delete | Remove portal users. Held separately from Portal User Administration so that removal can be restricted. | PortalTenantUserAdminDelete |
| Portal Configuration Access | Access the Portal Configuration area, covering portal details, appearance, footer and email settings. | PortalTenantAccess |
| Portal Configuration Edit | Update the Portal Configuration, including portal details, appearance, footer and email settings. | PortalTenantEdit |
| Portal User Administration | Add portal users, assign roles and link entities to them. Also grants access to the Portal Quick Link task. | PortalTenantUserAdmin |
| Portal User Dashboard Access | View the portal dashboard configuration. Dashboards are assigned per portal role. | DashboardAccess |
| Portal User Dashboard Edit | Create and update portal dashboards. | DashboardEdit |
| Portal User Role Access | View the details of the portal user roles configured for the tenant. Roles control which dashboards and business context a portal user can see; a portal user may hold up to five roles. | UserRoleAccess |
| Portal User Role Configuration | Create and update portal user role configuration. | UserRoleConfiguration |
| Portal User Role Delete | Delete portal user roles. | UserRoleDelete |
| Quick Link Access | View the portal users currently linked to an entity from the Portal Quick Link task, along with their status, relationship, email address and portal role. | QuickLinkAccess |
| Quick Link Edit | Link and unlink portal users on an entity from the Portal Quick Link task. | QuickLinkEdit |
| Domain Verification Edit | Manage email domain (add, verify, enable). | EmailDomainVerify |
Integration Flows
Configuration
| Permission Name | Description | Scope Reference |
|---|---|---|
| Auth Configuration Access | Access the authentication configurations used by integration flows to connect to external systems. | IntegrationFlowsAuthConfigurationAccess |
| Auth Configuration Edit | Create and edit the authentication configurations used by integration flows. | IntegrationFlowsAuthConfigurationEdit |
| Configuration Access | Access integration flow configurations in Flow Studio. | IntegrationFlowsConfigurationAccess |
| Configuration Edit | Create and edit integration flow configurations in Flow Studio. | IntegrationFlowsConfigurationEdit |
| Configuration Approve | Approve an integration flow configuration for publication. | IntegrationFlowsConfigurationApprove |
| Configuration Delete | Delete an integration flow configuration. | IntegrationFlowsConfigurationDelete |
Flow Interactions
| Permission Name | Description | Scope Reference |
|---|---|---|
| Flow API Trigger | Trigger an integration flow directly from its API endpoint, rather than from a scheduled or event-based trigger. | IntegrationFlowsFlowApiTrigger |
| Flow Debug Draft | Debug a draft flow, or re-run a flow in debug mode from the Execution Details view. | IntegrationFlowsTestExecution |
| Flow Debug Transformer Task | Debug the code inside a Transformer task. Grants visibility of data passing through the transformer, so it should be granted with the same care as access to the underlying data. | IntegrationFlowsTestTransformerTask |
| Flow Execution Details Read | View the step-level logs for a flow execution. Required to diagnose where and why a flow failed. | IntegrationFlowsFlowExecutionDetailsRead |
| Flow Execution Read | View the record of integration flow executions, including their status and history. | IntegrationFlowsFlowExecutionRead |
| Flow Execution Retry | Re-run a failed or incomplete integration flow execution. | IntegrationFlowsFlowExecutionRetry |
| Flow Task Close | Close or complete an Integrations Data Publish task within a journey, allowing the journey to progress where the integration cannot be completed successfully. | IntegrationFlowsFlowTaskClose |
| Flow Task Retry | Retry a failed Integrations Data Publish task from within a journey. | IntegrationFlowsFlowTaskRetry |
| Mapping Edit | Edit the data mapping configurations used by integration flows. | IntegrationFlowsMappingEdit |
Persisted Storage
| Permission Name | Description | Scope Reference |
|---|---|---|
| Persisted Storage Access | Provides read access to the list of files held in Persisted Storage as a paginated view in Flow Studio. | IntegrationFlowsPersistedStorageAccess |
| Persisted Storage Delete Record | Delete a file from Persisted Storage before its time-to-live expires. | IntegrationFlowsPersistedStorageDelete |
| Persisted Storage Get Record | View the contents of a non-sensitive file in Persisted Storage. Needed alongside Persisted Storage Access to inspect file content when debugging or reviewing a flow. | IntegrationFlowsPersistedStorageGet |
| Persisted Storage Get Sensitive Record | View the contents of a file marked as Sensitive in Persisted Storage. Held separately from the standard get permission so that files containing sensitive data can be restricted to a smaller group of users. | IntegrationFlowsPersistedStorageGetSensitive |
Logging Centre APIs
| Permission Name | Description | Scope Reference |
|---|---|---|
| Logging Centre Access | Access logs produced by Fenergo SaaS integration services, including checking logging status, searching for logs and retrieving log results. | LoggingCentreAccess |
| Logging Centre Edit | Change Logging Centre settings, including opting integration logging in or out. | LoggingCentreEdit |
Investment Account Management
Bank Accounts
| Permission Name | Description | Scope Reference |
|---|---|---|
| Delete Verified Bank Account Relationships | Delete the relationship between a verified bank account and an investor. | TransferAgencyDeleteVerifiedBankAccountRelationships |
Account Control Configuration
| Permission Name | Description | Scope Reference |
|---|---|---|
| Account Control Configuration Access | Access and view the tenant-wide Account Control Configuration settings for Investment Accounts. Settings are read-only without Edit permission. | AccountControlConfigurationAccess |
| Account Control Configuration Edit | Modify and save tenant-wide Account Control Configuration settings that control Investment Account behaviour. | AccountControlConfigurationEdit |
ISDA Amend
| Permission Name | Description | Scope Reference |
|---|---|---|
| Isda Access | Access the ISDA Amend configuration area. This permission is required in addition to ISDA Configuration. | IsdaAccess |
| Isda Configuration | Configure ISDA Amend, including S&P connection credentials, protocol activation and mappings to Policy, and ISDA scheduler frequency. This permission is required together with Isda Access to enter the configuration area. | IsdaConfiguration |
Journey Management
Journeys
| Permission Name | Description | Scope Reference |
|---|---|---|
| Journey Access | View Journey instances assigned to the user's team in Journey Hub. | JourneyAccess |
| Change Journey Access Layers | Change the Access Layers assigned to a Journey instance, controlling which users can access that Journey. | JourneyChangeAccessLayers |
| Completed Task Access | View a completed task, even when the user is not a member of the tasks assigned team. | JourneyCompletedTaskAccess |
| Journey Create | Create or launch new Journey instances. | JourneyCreate |
| Journey Edit | Progress an in-flight Journey by completing tasks and submitting review outcomes; this is operational Journey access rather than Journey configuration. | JourneyEdit |
| Journey Cancel | Cancel an in-flight Journey instance. | JourneyCancel |
| Journey Pause Instance | Pause or resume an entire Journey instance, including its stages and tasks with SLA configuration. | JourneyPauseInstance |
| Journey Pause Stage | Pause or resume an individual Journey stage and its tasks with SLA configuration. | JourneyPauseStage |
| Journey Pause Task | Pause or resume an individual in-progress Journey task. | JourneyPauseTask |
| Journey Reassign Read Only Task | Assign or change the teams that have read-only access to a Journey task. | JourneyReassignReadOnlyTask |
| Journey Reassign Task Owner & Team | Reassign both the Team and Owner of a Journey task when the user has access to the task's currently assigned Team. | JourneyReassignTask |
| Journey Reassign Task Owner Only | Reassign the Owner of a Journey task while leaving its assigned Team unchanged; access to the currently assigned Team is required. | JourneyReassignTaskOwnerOnly |
| Journey Reassign Task Owner, No Task Access | Reassign a task where the user does not have access to its currently assigned Team, including tasks that are sealed because their assigned Team is unavailable or inaccessible. | JourneyReassignOwnerNoTaskAccess |
| Journey Reopen Task | Reopen a completed Journey task so that the workflow can return to that task for further work. | JourneyReopenTask |
| Reassign Journey Owner and Team | Change both the Journey Owner and the Owner's Team for a Journey. | JourneyOwnerEdit |
| Reassign Journey Owner Only | Change the Journey Owner while leaving the Owner's Team unchanged. | JourneyOwnerEditOwnerOnly |
| Set Journey State | Set or change the configurable State assigned to a Journey instance from Journey Hub. | JourneyCustomStatusEdit |
| SLA Working Days Configuration Access | Access and view the SLA Configuration settings that define working days and the reference timezone used for Journey SLA calculations. | WorkingDaysAccess |
| SLA Working Days Configuration Edit | Modify and save the working days and reference timezone used when calculating Journey, Stage and Task SLAs. | WorkingDaysEdit |
| Unassign Journey or Task Owner | Clear the assigned Journey Owner or Task Owner without assigning a replacement, while retaining the existing Team assignment. | JourneyUnassignOwner |
Journey Builder
| Permission Name | Description | Scope Reference |
|---|---|---|
| Journey Builder Access | Access and view Journey definitions and their configuration in Journey Builder. | JourneyBuilderAccess |
| Journey Builder Edit | Create and modify Journey definitions, including creating Journey schemas and versions, editing draft or rejected versions, cloning versions and submitting changes for approval. | JourneyBuilderEdit |
| Journey Builder Approve | Approve or reject Journey definition versions submitted for approval. | JourneyBuilderApprove |
| Journey Builder Archive | Archive a Journey definition version. | JourneyBuilderArchive |
| Journey Builder Delete | Delete a Journey definition version or the complete Journey definition and all its versions. | JourneyBuilderDelete |
| Journey Launch Control Access | Access and view Journey Launch Controls that define when Journey Types can or cannot be initiated. | JourneyLaunchControlsAccess |
| Journey Launch Control Edit | Create and modify Journey Launch Controls, including conditions and team restrictions that determine whether a Journey Type can be launched. | JourneyLaunchControlsEdit |
| Journey Launch Control Delete | Delete configured Journey Launch Controls. | JourneyLaunchControlsDelete |
Journey Configuration Drawer
| Permission Name | Description | Scope Reference |
|---|---|---|
| Journey Configuration Edit | Modify Journey configuration settings and toggles. Typically granted to System Configuration users in lower-level environments and not typically granted in Production. | JourneyConfigurationEdit |
Journey Scheduler
| Permission Name | Description | Scope Reference |
|---|---|---|
| Journey Scheduler Access | Access and view Journey Scheduler and configured Journey Schedules. | JourneySchedulerAccess |
| Journey Scheduler Edit | Create and modify Journey Schedules, including schedule versions, draft or rejected versions, clones and schedule dates. | JourneySchedulerEdit |
| Journey Scheduler Approve | Submit Journey Schedule versions for approval and approve or reject submitted versions. | JourneySchedulerApprove |
| Journey Scheduler Archive | Archive a Journey Schedule version. | JourneySchedulerArchive |
| Journey Scheduler Delete | Delete Journey Schedule versions, complete Journey Schedules and Journey Schedule date records. | JourneySchedulerDelete |
| Journey Scheduler Trigger | Trigger the scheduler via its endpoint (vs waiting for the daily scheduled run). This is not usually granted to users in a live tenant, but rather used to accelerate testing. | JourneySchedulerTrigger |
Loan Origination
Financial Analysis
| Permission Name | Description | Scope Reference |
|---|---|---|
| Financial Analysis Report Access | Download the completed Financial Analysis task data as a CSV report reflecting the financial data currently displayed for the selected entity or deal. | FinancialAnalysisReport |
| Financial Analysis Access | Access and view Financial Analysis and Capacity to Service records, versions and associated data within the relevant Journey context. | FinancialAnalysisAccess |
| Financial Analysis Edit | Create and update Financial Analysis and Capacity to Service records and versions, including financial data, scenarios, summaries and completion status. | FinancialAnalysisEdit |
| Financial Analysis Configuration Access | Access and view Financial Analysis configurations and their versions. | FinancialAnalysisConfigurationAccess |
| Financial Analysis Configuration Create | Create new Financial Analysis configurations and create new draft versions of existing configurations, including submitting configuration versions for approval. | FinancialAnalysisConfigurationCreate |
| Financial Analysis Configuration Edit | Modify draft or rejected Financial Analysis configuration versions and clone existing configuration versions. | FinancialAnalysisConfigurationEdit |
| Financial Analysis Configuration Approve | Approve or reject Financial Analysis configuration versions submitted for approval. | FinancialAnalysisConfigurationApprove |
| Financial Analysis Configuration Archive | Archive a Financial Analysis configuration version. | FinancialAnalysisConfigurationArchive |
| Financial Analysis Configuration Delete | Delete a Financial Analysis configuration and all of its versions. | FinancialAnalysisConfigurationDelete |
| Financial Analysis Import Configuration Access | Access and view Financial Analysis Import providers and their configuration, mappings and adapter schemas. | FinancialImportProviderAccess |
| Financial Analysis Import Configuration Create | Create Financial Analysis Import provider configuration components, including provider mappings and adapter schemas. | FinancialImportProviderCreate |
| Financial Analysis Import Configuration Edit | Modify Financial Analysis Import providers, mappings and adapter schemas, including enabling or disabling an import provider. | FinancialImportProviderEdit |
| Financial Analysis Import Configuration Delete | Delete Financial Analysis Import provider configuration components, including provider mappings and adapter schemas. | FinancialImportProviderDelete |
Capacity to Service
| Permission Name | Description | Scope Reference |
|---|---|---|
| Capacity to Service Configuration Access | Access and view Capacity to Service configurations and their versions. | AllocationConfigurationAccess |
| Capacity to Service Configuration Create | Create new Capacity to Service configurations and create new draft versions of existing configurations. | AllocationConfigurationCreate |
| Capacity to Service Configuration Edit | Modify draft or rejected Capacity to Service configuration versions and clone existing configuration versions. | AllocationConfigurationEdit |
| Capacity to Service Configuration Approve | Approve or reject Capacity to Service configuration versions submitted for approval. | AllocationConfigurationApprove |
| Capacity to Service Configuration Archive | Archive a Capacity to Service configuration version. | AllocationConfigurationArchive |
| Capacity to Service Configuration Delete | Delete a Capacity to Service configuration and all of its versions. | AllocationConfigurationDelete |
Credit Screening
| Permission Name | Description | Scope Reference |
|---|---|---|
| Automated Credit Screening Access | Access and view automated Credit Screening enquiries and outcomes returned by configured screening providers. This permission is also accepted by the APIs for viewing Credit Screening provider configuration. | CreditScreeningAccess |
| Automated Credit Screening Delete | Delete automated Credit Screening enquiries. The same permission is also accepted by the APIs for deleting Credit Screening providers and associated provider configuration, mappings and adapter schemas. | CreditScreeningDelete |
| Manual Credit Screening Access | Access and view Manual Credit Screening records, versions and screening history captured for entities within Journeys. | ManualCreditScreeningAccess |
| Manual Credit Screening Create | Create a new Manual Credit Screening record and its initial draft version for an entity within a Journey task. | ManualCreditScreeningCreate |
| Manual Credit Screening Edit | Create new versions and update, complete or reject draft Manual Credit Screening records, including capturing manually sourced screening information. | ManualCreditScreeningEdit |
Credit Assessment
| Permission Name | Description | Scope Reference |
|---|---|---|
| Automated Credit Assessment Access | Access and view automated Credit Assessment enquiries and outcomes returned by configured assessment providers. This permission is also accepted by the APIs for viewing Credit Assessment provider configuration. | AutomatedCreditAssessmentAccess |
| Automated Credit Assessment Delete | Delete automated Credit Assessment enquiries. The same permission is also accepted by the APIs for deleting Credit Assessment providers and associated provider configuration, mappings and adapter schemas. | AutomatedCreditAssessmentDelete |
| Manual Credit Assessment Access | Access and view Manual Credit Assessment records, versions and assessment history captured within Journeys. | CreditAssessmentAccess |
| Manual Credit Assessment Edit | Create and update Manual Credit Assessment records and draft versions, including capturing assessment decisions and completing assessments within a Journey. | CreditAssessmentEdit |
| Manual Credit Assessment Delete | Delete a Manual Credit Assessment set and all assessments contained within it. | CreditAssessmentDelete |
Credit Data Sources
| Permission Name | Description | Scope Reference |
|---|---|---|
| Credit Assessment Configuration Access | Access and view automated Credit Assessment providers and their provider configuration, mappings, adapter schemas and configuration status. | CreditAssessmentConfigurationAccess |
| Credit Assessment Configuration Create | Create automated Credit Assessment providers and associated provider configuration, mappings and adapter schemas. | CreditAssessmentConfigurationCreate |
| Credit Assessment Configuration Edit | Modify automated Credit Assessment providers, provider configuration, mappings and adapter schemas, including enabling or disabling a provider. | CreditAssessmentConfigurationEdit |
| Credit Assessment Configuration Delete | Delete automated Credit Assessment providers and associated provider configuration, mappings and adapter schemas. | CreditAssessmentConfigurationDelete |
| Credit Screening Configuration Access | Access and view Credit Screening providers and their provider configuration, mappings, adapter schemas and configuration status. | CreditScreeningDataSourcesAccess |
| Credit Screening Configuration Create | Create Credit Screening providers and associated provider configuration, mappings and adapter schemas. | CreditScreeningDataSourcesCreate |
| Credit Screening Configuration Edit | Modify Credit Screening providers, provider configuration, mappings and adapter schemas, including enabling or disabling a provider. | CreditScreeningDataSourcesEdit |
| Credit Screening Configuration Delete | Delete Credit Screening providers and associated provider configuration, mappings and adapter schemas. | CreditScreeningDataSourcesDelete |
Credit Policy Configuration
| Permission Name | Description | Scope Reference |
|---|---|---|
| Credit Policy Configuration Access | Access and view configurations within the Credit Policy feature. | CreditPolicyAccess |
| Credit Policy Configuration Edit | Create new and modify existing Credit Policy configuration versions. | CreditPolicyEdit |
| Credit Policy Configuration Approve | Approve Credit Policy configuration versions. | CreditPolicyApprove |
| Credit Policy Configuration Archive | Archive Credit Policy configuration versions. | CreditPolicyArchive |
| Credit Policy Configuration Delete | Delete draft Credit Policy configuration versions. | CreditPolicyDelete |
Collateral Management
| Permission Name | Description | Scope Reference |
|---|---|---|
| Collateral Access | Access Collateral and Asset records and drafts, including Journey-specific collateral data and related collateral. | CollateralAccess |
| Collateral Access and Search | Access, search and retrieve Collateral and Asset records and drafts, including Journey-specific collateral data and related collateral. | CollateralAccessAndSearch |
| Collateral Edit | Create and update Collateral and Asset records and drafts within a Journey, including deleting unverified drafts. | CollateralEdit |
| Collateral Verification | Allows API command to verify collateral (same operation as the Verify Collateral task). | CollateralVerification |
| Collateral Approve | Verify Collateral and Asset drafts so that draft information is merged into the verified Collateral or Asset record. | CollateralApprove |
Covenants and Conditions
| Permission Name | Description | Scope Reference |
|---|---|---|
| Covenants & Conditions Access | Access and view Covenants & Conditions sets and their versions for a Deal. | CovenantsConditionsAccess |
| Covenants & Conditions Edit | Create and update Covenants & Conditions sets and draft versions, including completing and verifying Covenants & Conditions versions within a Journey. | CovenantsConditionsEdit |
Calculated Fields
| Permission Name | Description | Scope Reference |
|---|---|---|
| Calculation Configuration Access | Access and view Calculation Configuration and existing formulas used by Calculated Fields. | CalculationEngineAccess |
| Calculation Configuration Create | Create new calculation formulas, including defining formula names, descriptions, data sources and formula elements. | CalculationEngineCreate |
| Calculation Configuration Edit | Modify calculation formulas using the formula builder, including operators, datakeys, values, functions and data sources. | CalculationEngineEdit |
| Calculation Configuration Approve | Approve calculation formula configurations for publication. | CalculationEngineApprove |
| Calculation Configuration Archive | Archive calculation formula configurations. | CalculationEngineArchive |
| Calculation Configuration Delete | Delete calculation formula configurations. | CalculationEngineDelete |
Localisation
| Permission Name | Description | Scope Reference |
|---|---|---|
| Localisation Access | Access and view Localisation configuration, including tenant language packs, versions, supported languages and translation contexts. | LocalisationAccess |
| Localisation Edit | Create and modify Localisation language packs and draft versions, including translation contexts and files, and submit versions for approval. | LocalisationEdit |
| Localisation Approve | Approve or reject Localisation versions submitted for approval. | LocalisationApprove |
| Localisation Archive | Archive an existing Localisation version. | LocalisationArchive |
| Localisation Delete | Delete Localisation versions, complete Localisations and their versions, or individual Localisation contexts. | LocalisationDelete |
Narratives
| Permission Name | Description | Scope Reference |
|---|---|---|
| Narratives Access | Access the Narratives tab on the entity profile page. Required before any individual narrative category permission takes effect. | NarrativesAccess |
| Business Narratives Access | View business narratives on the Narratives tab. | NarrativesBusinessAccess |
| Business Narratives Create | Add new business narratives. Displays the Add control for the Business Narratives category. | NarrativesBusinessCreate |
| Business Narratives Edit | Edit existing business narratives. | NarrativesBusinessEdit |
| Business Narratives Delete | Delete business narratives. | NarrativesBusinessDelete |
| Compliance Narratives Access | View compliance narratives on the Narratives tab. | NarrativesComplianceAccess |
| Compliance Narratives Create | Add new compliance narratives. Displays the Add control for the Compliance Narratives category. | NarrativesComplianceCreate |
| Compliance Narratives Edit | Edit existing compliance narratives. | NarrativesComplianceEdit |
| Compliance Narratives Delete | Delete compliance narratives. | NarrativesComplianceDelete |
Policy
Policy Configuration
| Permission Name | Description | Scope Reference |
|---|---|---|
| Policy Configuration Access | Access the Policy Configuration feature. Typically granted to System Configuration users in lower-level environments, and generally only to Application Support Teams in Production. | PolicyConfigurationAccess |
| Policy Configuration Edit | Create and modify policy configuration. Typically withheld from users in Production. | PolicyConfigurationEdit |
| Policy Configuration Approval | Approve a policy configuration version for publication. Typically withheld from users in Production. | PolicyConfigurationApprove |
| Policy Configuration Archive | Archive within the Policy Config. | PolicyConfigurationArchive |
| Policy Configuration Delete | Delete within the Policy Config. | PolicyConfigurationDelete |
| Policy Workspace Configuration Access | Access Policy v2 Workspaces. | PolicyWorkspaceConfigurationAccess |
| Policy Workspace Configuration Edit | Interact with the Policy v2 Workspace Config (e.g. Edit). | PolicyWorkspaceConfigurationEdit |
Policy Search
| Permission Name | Description | Scope Reference |
|---|---|---|
| Policy Search and Requirement Scope | Search Policy and retrieve or evaluate the Policy requirements that are in scope for a given entity or Journey context. | PolicySearch |
Policy Simulator
| Permission Name | Description | Scope Reference |
|---|---|---|
| Policy Simulator Access | Policy Simulator is used to test and validate Policy configuration behaviour before publication. | PolicySimulatorAccess |
Product Enablement
Product Task and Journey interactions
| Permission Name | Description | Scope Reference |
|---|---|---|
| Product Access & Search | Search for and access Product records within Fenergo SaaS. | ProductAccessAndSearch |
| Product Edit | Create and edit Product draft records within a Journey, including maintaining Product data before verification. | ProductEdit |
| Product Approve | Required to invoke the Verify Product Draft command endpoint, which publishes Product changes captured in a draft (via a Journey or otherwise) to the verified Product record. | ProductApprove |
| Product Conflict Resolution Access | View Product conflicts within the Products tab of a Conflict Resolution task in a Journey. | ProductConflictResolutionAccess |
| Product Conflict Resolution Edit | Resolve Product conflicts by selecting which conflicting values to retain in the Product draft. Requires Product Conflict Resolution Access and Product Edit. | ProductConflictResolutionEdit |
| Product Offboarding | Offboard an active Product or re-onboard an offboarded Product within a Journey, creating a draft that is finalized through Product verification. | ProductOffboard |
| Product Proposed Changes Access | View Product changes within the Products tab of a Proposed Changes task in a Journey. | ProductProposedChangesAccess |
| Product Proposed Changes Edit | Resolve proposed Product changes by selecting which values to retain in the verified Product. Requires Product Proposed Changes Access and Product Edit. | ProductProposedChangesEdit |
| Product Requirement Scope | View and interact with Product-scoped data and document requirements presented within Journey tasks. | ProductConfigurationSearch |
Product Configuration
| Permission Name | Description | Scope Reference |
|---|---|---|
| Product Configuration Access | Access and view Product Configuration and Product Requirement Sets. | ProductConfigurationAccess |
| Product Configuration Edit | Create Product Requirement Sets, modify draft versions and submit drafts for approval. | ProductConfigurationEdit |
| Product Configuration Approval | Approve Product Requirement Set versions submitted for publication. | ProductConfigurationApprove |
| Product Configuration Archive | Archive a Product Requirement Set version. | ProductConfigurationArchive |
| Product Configuration Delete | Delete a Product Requirement Set version or the complete Product Requirement Set record. | ProductConfigurationDelete |
Deals
| Permission Name | Description | Scope Reference |
|---|---|---|
| Deal Access and Search | Search for and access Deal records, including Deal information available within the context of a Journey. | DealAccessAndSearch |
| Deal Create | Create new Deals and associated Deal drafts for capture within a Journey. | DealCreate |
| Deal Edit | Edit Deal draft records within a Journey, including creating the drafts required to update an existing verified Deal. | DealEdit |
| Deal Approve | Ability to approve a deal within the Manage Deals task. | DealApprove |
| Deal Delete | Delete Deals or Deal drafts captured in error before the Deal has been verified. Verified Deals cannot be deleted. | DealDelete |
| Deal Requirement Scope | View and interact with Deal requirements that are in scope within a Journey. | DealRequirementScope |
Deal Configuration
| Permission Name | Description | Scope Reference |
|---|---|---|
| Deal Configuration Access | Access and view Deal Configuration and configured Deal Requirement Sets. | DealConfigurationAccess |
| Deal Configuration Edit | Create Deal Requirement Sets, create and modify draft versions, maintain requirements and submit versions for approval. | DealConfigurationEdit |
| Deal Configuration Approve | Approve Deal Requirement Set versions submitted for publication. | DealConfigurationApprove |
| Deal Configuration Archive | Archive a Deal Requirement Set version. | DealConfigurationArchive |
| Deal Configuration Delete | Delete Deal Requirement Set versions or complete Requirement Set records, including requirements within a configurable version. | DealConfigurationDelete |
Reference Data
| Permission Name | Description | Scope Reference |
|---|---|---|
| Lookup Access | Interact with Reference Data lookups used across the application. Required by users who need to use lookup-backed fields and is also required to interact with the Reference Data feature. | LookupAccess |
| Reference Data Editor Access | Access and view the Reference Data feature, including Reference Data lists and CSV download/upload functionality. Also requires Lookup Access. | ReferenceDataEditorAccess |
| Reference Data Editor Edit | Create new Reference Data lists and new draft versions, modify draft or rejected versions, add or remove values, import CSV updates and submit changes for approval. Also requires Lookup Access. | ReferenceDataEditorEdit |
| Reference Data Editor Approve | Approve or reject Reference Data list versions submitted for approval. | ReferenceDataEditorApprove |
| Reference Data Editor Archive | Archive a Reference Data list version. | ReferenceDataEditorArchive |
| Reference Data Editor Delete | Delete Reference Data lists and their versions, including linked lookup records and versions. System Lookups cannot be deleted. | ReferenceDataEditorDelete |
Related Party Management
| Permission Name | Description | Scope Reference |
|---|---|---|
| Association Access | View an entity's hierarchy and Related Parties, including association details. Does not permit association data to be edited. | AssociationAccess |
| Association Edit | Add new draft Related Party associations and edit existing draft associations within a Journey. | AssociationEditOnly |
| Association Verification | Verify draft Related Party associations and resolve conflicts between draft and verified hierarchies. | AssociationVerification |
| Association Delete | Delete draft associations or mark verified associations for removal through the association lifecycle. | AssociationDeleteOnly |
| Association Edit & Delete | Fully maintain Related Parties within the Hierarchy Capture task, including adding, editing and removing associations. | AssociationEdit |
| Association Edit & Link Only | Add or edit Related Party associations by linking existing entities only; does not allow new entities to be created as part of the linking process. | AssociationEditAndLinkOnly |
| Association Edit & Partial Delete | Add, edit and remove Related Party associations, but prevents removal of all associations between the same source and target entities. | AssociationEditAndPartialDelete |
Review Manager
| Permission Name | Description | Scope Reference |
|---|---|---|
| Deferred Document Requirements Review Config Access | Access and view the Document Requirements tab in Review Journey Scheduling configuration. | DeferredDocRequirementsReviewConfigAccess |
| Deferred Document Requirements Review Config Edit | Configure deferred Document Requirement reviews, including enabling or disabling the setting and selecting the Review Journey to launch. | DeferredDocRequirementsReviewConfigEdit |
| Review Journey Scheduling Access | Access and view the Scoping Rules used to determine Review Journey scheduling. Product Configuration Access is additionally required to view the Product Scoping Rules tab. | ReviewJourneySchedulingAccess |
| Review Journey Scheduling Edit | Create new Review Journey Scheduling Scoping Rules and save draft versions. | ReviewJourneySchedulingEdit |
| Review Journey Scheduling Approve | Submit draft Review Journey Scheduling Scoping Rules for approval and approve or reject submitted versions. | ReviewJourneySchedulingApprove |
| Review Journey Scheduling Archive | Archive published Review Journey Scheduling Scoping Rule versions. | ReviewJourneySchedulingArchive |
| Review Journey Scheduling Delete | Delete Review Journey Scheduling Scoping Rule instances and draft versions. | ReviewJourneySchedulingDelete |
| Review Manager Access | Access the Review Manager dashboard from the main navigation. | ReviewManagerAccess |
| Review Manager Configuration Access | Access and view Review Manager dashboard configuration, including the configured dashboard columns. | ReviewManagerConfigurationAccess |
| Review Manager Configuration Edit | Modify Review Manager dashboard configuration, including the columns displayed on the dashboard. | ReviewManagerConfigurationEdit |
| Scheduled Review Access | View an entity's Scheduled Reviews on the Entity Profile or through the Review Query API. Journey Access also provides visibility of Scheduled Reviews. | ScheduledReviewAccess |
| Scheduled Review Edit | Create and update Scheduled Review records. | ScheduledReviewEdit |
| Scheduled Review Delete | Delete Scheduled Review records. | ScheduledReviewDelete |
Risk
Risk Configuration
| Permission Name | Description | Scope Reference |
|---|---|---|
| Risk Calculator Access | Access risk calculator. | RiskCalculatorAccess |
| Risk Configuration Access | Access the Risk Configuration feature. Typically granted to System Configuration users in lower-level environments, and generally only to Application Support Teams in Production. | RiskConfigurationAccess |
| Risk Configuration Edit | Create and modify risk configuration. Typically withheld from users in Production. | RiskConfigurationEdit |
| Risk Configuration Approve | Approve or reject risk configuration models. Typically withheld from users in Production. | RiskConfigurationApprove |
| Risk Configuration Archive | Archive risk configuration models. | RiskConfigurationArchive |
| Risk Configuration Delete | Delete risk configuration models. | RiskConfigurationDelete |
Risk Impact Assessment
| Permission Name | Description | Scope Reference |
|---|---|---|
| Risk Impact Assessment Access | Access Risk Impact Assessments. | RiskImpactAssessmentAccess |
| Risk Impact Assessment Edit | Create and edit Risk Impact Assessments. | RiskImpactAssessmentEdit |
Screening
Screening Task interactions
| Permission Name | Description | Scope Reference |
|---|---|---|
| Screening Access | Access and view screening results, including match details, classifications and materiality assessments. | ScreeningAccess |
| Screening Create | Create a new screening batch to screen one or more entities against configured screening providers. | ScreeningCreate |
| Screening Edit | Review and action screening results, including resolving matches, recording classifications or materiality assessments and completing screening batches. | ScreeningEdit |
| Screening Approve | Approve or reject screening escalation tasks where this approval model is used. | ScreeningApprove |
| Screening Delete | Delete an existing screening batch. | ScreeningCancel |
Screening Configuration
| Permission Name | Description | Scope Reference |
|---|---|---|
| Screening Configuration Access | Access and view Screening configuration and configured Screening Scoping Rule Sets. | ScreeningConfigurationAccess |
| Screening Configuration Create | Create new Screening Scoping Rule Sets and their initial draft versions. | ScreeningConfigurationCreate |
| Screening Configuration Edit | Create new versions of existing Screening Scoping Rule Sets, modify draft versions and submit them for approval. | ScreeningConfigurationEdit |
| Screening Configuration Approve | Approve or reject Screening Scoping Rule Set versions submitted for approval. | ScreeningConfigurationApprove |
| Screening Configuration Archive | Archive a Screening Scoping Rule Set version. | ScreeningConfigurationArchive |
| Screening Configuration Delete | Delete a Screening Scoping Rule Set version or the complete Scoping Rule Set and all its versions. | ScreeningConfigurationDelete |
Support
| Permission Name | Description | Scope Reference |
|---|---|---|
| Intercom Access | Enables users to directly chat with Fenergo Support and raise support tickets. | IntercomAccess |
Transaction Monitoring
Alerts and Investigation
| Permission Name | Description | Scope Reference |
|---|---|---|
| Alert Access | Open a Transaction Monitoring alert to view its details, associated transactions and investigation information. | AlertAccess |
| Alert Create | Create manual transactional or non-transactional alerts from the UI. Displays the Create Alert control on the Entity Alerts and Entity Transactions tabs. | AlertCreate |
| Alert Dashboard Access | Access and view the Transaction Monitoring Alert Dashboard. | AlertDashboardAccess |
| Alert Dashboard Configuration Edit | Configure the columns displayed on the Alert Dashboard. | AlertDashboardConfigurationEdit |
| Entity Profile Transaction View | View transaction details recorded for an entity from the Entity Profile. | EntityProfileTransactionView |
| TM Risk Configuration Access | Access and view Transaction Monitoring risk configuration, including configuration used for Behavioural Risk. | TMRiskConfigurationAccess |
| TM Risk Configuration Edit | Create and update Transaction Monitoring risk configuration, including Behavioural Risk settings and scoping conditions. | TMRiskConfigurationEdit |
| TM Risk Configuration Approve | Approve Transaction Monitoring risk configuration. Typically restricted to configuration administrators and not normally granted to operational users in Production. | TMRiskConfigurationApprove |
| TM Risk Configuration Delete | Delete Transaction Monitoring risk configuration. Typically restricted to configuration administrators and not normally granted to operational users in Production. | TMRiskConfigurationDelete |
| Transactions Api Access | Access and use the Transaction Monitoring Transactions API. | TransactionsApiAccess |
| Insights Access | Access to the Insights feature which provides Transaction Monitoring performance and analytical views. | InsightsAccess |
| Whitelist Access | Access and view Entity Whitelist entries. | EntityWhitelistingAccess |
| Whitelist Edit | Create new Entity Whitelist requests and update existing whitelist entries. | EntityWhitelistingEdit |
| Whitelist Approve | Approve Entity Whitelist requests added for an entity. | EntityWhitelistingApprove |
| Whitelist Delete | Remove an Entity Whitelist entry. | EntityWhitelistingDelete |
Access
| Permission Name | Description | Scope Reference |
|---|---|---|
| Observability Access | Access the Transaction Monitoring Observability dashboard. | ObservabilityViewAccess |
Detection Rules
| Permission Name | Description | Scope Reference |
|---|---|---|
| Rule View List | View the list of Transaction Monitoring detection rules. | RuleViewListAccess |
| Rule View Details | View the details of a Transaction Monitoring detection rule. | RuleViewDetailsAccess |
| Rule Draft Edit | Edit a draft Transaction Monitoring detection rule. | RuleDraftEditAccess |
| Rule Publish | Publish a Transaction Monitoring detection rule. | RulePublishAccess |
| Rule Archive | Archive a Transaction Monitoring detection rule. | RuleArchiveAccess |
| Rule Draft Import/Export | Import and export draft Transaction Monitoring detection rules. | RuleDraftImportExportAccess |
| Rule Audit Activity | View the audit activity trail for Rules. | DetectionRuleAuditActivityAccess |
| Rule Audit Export | Request, list and download Rule Audit Export reports. | DetectionRuleAuditExportAccess |
| Rule Backtest View | View backtest results for a Transaction Monitoring detection rule. | RuleBacktestViewAccess |
| Rule Backtest Run | Run a backtest on a Transaction Monitoring detection rule. | RuleBacktestRunAccess |
| Rule Group View | View Transaction Monitoring Rule Groups. | RuleGroupViewAccess |
| Rule Group Create | Create Transaction Monitoring Rule Groups. | RuleGroupCreateAccess |
| Rule Group Edit | Edit Transaction Monitoring Rule Groups. | RuleGroupEditAccess |
| Rule Group Delete | Delete Transaction Monitoring Rule Groups. | RuleGroupDeleteAccess |
| Rule Group Activity View | View activity for Transaction Monitoring Rule Groups. | RuleGroupActivityViewAccess |
Rules Hub
| Permission Name | Description | Scope Reference |
|---|---|---|
| Rules Hub Access | Access rules hub, and see rule details. | RulesHubAccess |
| Rules Hub Edit | Add new or edit existing rules. | RulesHubEdit |
| Rules Hub Approval | Approve configuration version for publication within the Rules Hub. | RulesHubApprove |
| Rules Hub Delete | Delete rules within the Rules Hub. | RulesHubDelete |
Deprecated Permissions
The following permissions are retained for backward compatibility but have been superseded. Avoid assigning them to new Teams.
Document Management
| Permission Name | Description | Scope Reference |
|---|---|---|
| Document Management Archive (Legacy) | Combines archive and unarchive into a single permission. Retained for backward compatibility and scheduled for removal. Use the separate Document Management - Archive and Document Management - Unarchive permissions instead. | DocumentManagementArchive |
Loan Origination
Financial Analysis
| Permission Name | Description | Scope Reference |
|---|---|---|
| Financial Analysis Approve | Used to approve settings for Financial Analysis. | FinancialAnalysisApprove |
Transaction Monitoring
Access
| Permission Name | Description | Scope Reference |
|---|---|---|
| Compliance Officer Role Access | Superseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Compliance Officer. | TransactionMonitoringComplianceOfficerAccess |
| Customer Success Role Access | Superseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Customer Success. | TransactionMonitoringCustomerSuccessAccess |
| Manager Role Access | Superseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Manager. | TransactionMonitoringManagerAccess |
| MLRO Role Access | Superseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a MLRO. | TransactionMonitoringMLROAccess |
| Product Admin Role Access | Superseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Product Admin. | TransactionMonitoringProductAdminAccess |
| Screening Analyst Role Access | Superseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Screening Analyst. | TransactionMonitoringScreeningAnalystAccess |
| Senior Compliance Officer Role Access | Superseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Senior Compliance Officer. | TransactionMonitoringSeniorComplianceOfficerAccess |
| Super User Role Access | Superseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Super User. | TransactionMonitoringSuperUserAccess |
| TMAnalyst Role Access | Superseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a TM Analyst. | TransactionMonitoringTMAnalystAccess |
| Alert Configuration Access | Controls access to the Alert Metadata Configuration section within the Reference Data domain. | AlertConfigurationAccess |
| Alert Configuration Approve | Controls approval to the Alert Metadata Configuration section within the Reference Data domain. | AlertConfigurationApprove |
| Alert Configuration Edit | Controls the ability to edit the Alert Metadata Configuration section within the Reference Data domain. | AlertConfigurationEdit |