Skip to main content

Permissions Catalogue

Permissions are pre-defined within the Fenergo SaaS application and represent a series of functional capabilities across the various features within the application.

Permissions determine what a user can do within the system. They cover administrative, operational and configuration based user activities.

From an Operational user's POV, permissions control what the user can access, create, cancel, etc. For example, a user may have permission to initiate journey, access client entity data, and trigger screening. Permissions also govern what the Configuration user is allowed to do within the system whether including operations such as create, edit, and approve with respect to configuration sets. For example, a user may have permission to create Policy drafts, edit the requirements within it, and then approve any changes to policies.

Permissions are organized by Domain and are pre-defined per specific API capabilities within the system. Permissions are broken up into the following categories:

  • Access - the ability to access a feature
  • Edit - the ability to edit within a feature
  • Create - the ability to create an instance of an object related to feature
  • Cancel - the ability to cancel an activity within a feature
  • Delete - the ability to delete within a feature
  • Approve - the ability to approve within a feature
  • Archive - the ability to archive within a feature

Permissions are added to Teams. While the individual permissions are pre-configured and cannot be changed, Teams are configurable and the the combinations of permissions contained within team are fully configurable.

This document also includes information on configuration permissions that are pre-defined within the system, but are typically only provisioned to System Configuration or Application Support Teams.

tip

Refer to the Access Management User Guide for more details on how Permissions are used within Fenergo SaaS

Current Permissions​

Access Management​

User Management​

Permission NameDescriptionScope Reference
Security User AdministrationAccess the User Administration feature to manage user accounts.UserAdministration
Security Create New UserCreate new user accounts.SecurityCreateUser
Security Edit UsersEdit existing user accounts.SecurityEditUser
Security Remove UsersDelete user accounts.SecurityDeleteUser

Team & Access Layer Management​

Permission NameDescriptionScope Reference
Security Configuration AccessAccess the Security Configuration feature, where teams and permissions are managed.SecurityConfigAccess
Security Configuration CreateCreate new teams and assign permissions to them.SecurityConfigCreate
Security Configuration EditEdit existing teams, including the permissions assigned to them.SecurityConfigEdit
Security Configuration DeleteDelete teams.SecurityConfigDelete
Landing Page EditSet the field 'Default landing page for team members when logging in'.LandingPageEdit

Client Management​

Permission NameDescriptionScope Reference
Security Client AdministrationView clients via Client Management.ClientAdministration
Security Client Secret AdministrationAccess client secrets via Secret Management - actual secret values are only visible on initial generation.SecretAdministration
Security Create New ClientCreate new clients.SecurityCreateClient
Security Create New Client SecretCreate new client secrets.SecurityCreateSecret
Security Edit ClientsEdit client.SecurityEditClient
Security Remove Client SecretsRemove client secrets.SecurityDeleteSecret
Security Remove ClientsRemove client.SecurityDeleteClient

External Authentication​

Permission NameDescriptionScope Reference
External Authentication Configuration AccessAccess existing External Authentication Configuration via query API.ExternalAuthenticationAccess
External Authentication Configuration CreateCreate new External Authentication Configuration via command API. This supports mTLS (Mutual Transport Layer Security) and OAuth 2.0 Client Credentials on outbound traffic originating from the following services Webhooks, External Data Adapters and Screening Adapters.ExternalAuthenticationCreate
External Authentication Configuration EditEdit existing External Authentication Configuration via command API.ExternalAuthenticationEdit
External Authentication Configuration DeleteDelete existing External Authentication Configuration via command API.ExternalAuthenticationDelete

Audit​

Permission NameDescriptionScope Reference
Audit Access & SearchAccess and search the system audit log, providing visibility of the system audit trail, including the audit history of individual entities and their journeys.AuditAccessAndSearch

Bulk Upload and Request​

Bulk Request​

Permission NameDescriptionScope Reference
Bulk Request AccessAccess the Bulk Request feature to submit and monitor bulk operations to update entity data.BulkLoadAccess

Change Management​

Conflict Resolution​

Permission NameDescriptionScope Reference
Conflict Resolution AccessAccess conflict resolution records within a journey.ConflictResolutionAccess
Conflict Resolution EditEdit conflict resolution records within a journey.ConflictResolutionEdit

Proposed Changes​

Permission NameDescriptionScope Reference
Proposed Changes AccessAccess and view Proposed Changes within a journey.ProposedChangesAccess
Proposed Changes EditAction Proposed Changes by accepting or rejecting them within a journey.ProposedChangesEdit

Review and Approval​

Permission NameDescriptionScope Reference
Review & Approval AccessAccess the Review & Approval task.ReviewApprovalAccess
Review & Approval CommentLeave comments on desired data points that require attention.ReviewApprovalComment
Review & Approval Configuration AccessAccess Review & Approval Configuration.ReviewApprovalConfigurationAccess
Review & Approval Configuration CreateCreate Review & Approval Configuration.ReviewApprovalConfigurationCreate
Review & Approval Configuration EditEdit Review & Approval Configuration.ReviewApprovalConfigurationEdit
Review & Approval Configuration ApproveApprove Review & Approval Configuration.ReviewApprovalConfigurationApprove
Review & Approval Configuration ArchiveArchive Review & Approval Configuration.ReviewApprovalConfigurationArchive
Review & Approval Configuration DeleteDelete Review & Approval Configuration.ReviewApprovalConfigurationDelete
Review & Approval DecisionMake a decision on the Review & Approval task.ReviewApprovalDecision
Review & Approval Resolve CommentsResolve comments across the Review & Approval task.ReviewApprovalResolveComments

Comments​

Permission NameDescriptionScope Reference
Access to CommentsAccess the comments drawer to view Comments and @mentions on an Entity Profile or within a Journey.CommentsAccess
Create a Comment ThreadCreate a comment thread.CommentsCreate
Delete Any CommentDelete any comment.CommentsDeleteAny
Delete Your Own CommentsDelete your own comments.CommentsDeleteOwn
Reply to a Comment ThreadReply to a comment thread.CommentsReply

Configuration Baseline​

Permission NameDescriptionScope Reference
Configuration Baseline AccessAccess configuration baseline records via API.ConfigBaselineAccess
Configuration Baseline EditEdit configuration baseline models via API.ConfigBaselineEdit

Configuration Exchange​

Permission NameDescriptionScope Reference
Configuration Exchange AccessAccess configuration exchange import records.ConfigurationExchangeAccess
Configuration Exchange EditCreate an import record and select configuration to import from a source tenant this target tenant.ConfigurationExchangeEdit
Configuration Exchange PublishEnables the option to Publish configuration on Import (vs importing versioned configuration in a draft state).ConfigurationExchangePublish

Dashboards and Reporting​

Reporting​

Permission NameDescriptionScope Reference
Reporting AccessAccess to Advanced Reporting and Legacy Reporting. In Advanced Reporting, view saved queries and their SQL; in Legacy Reporting, run the out-of-the-box reports.ReportingAccess
Reporting EditCreate, edit, preview and save Advanced Reporting queries.ReportingEdit
Reporting DeleteDelete saved Advanced Reporting queries.ReportingDelete
Reporting ExecuteRun Advanced Reporting queries and download generated reports.ReportingExecute
Reporting AdminAccess to Reporting Configurations, such as to configure branding for generated reports.ReportingAdmin

Advanced Dashboards​

Permission NameDescriptionScope Reference
Advanced Dashboard Configuration EditEdit configuration for Advanced Dashboards.AdvancedDashboardConfigurationEdit
Advanced Dashboards AccessAccess Advanced Dashboards.AdvancedDashboardAccess
Bulk Actions on Tasks DashboardBulk complete tasks as well as update Entity Data for those selected Tasks' on the Tasks Dashboard.TaskBulkCompletion

Dashboards​

Permission NameDescriptionScope Reference
Task Dashboard AccessAccess task dashboard.TaskDashboardAccess
Team Management Dashboard AccessAccess team dashboard.TeamDashboardAccess

Business Metrics​

Permission NameDescriptionScope Reference
Business Metrics AccessAccess Business Metrics.BusinessMetricsAccess
Business Metrics EditEdit Business Metrics.BusinessMetricsEdit

Command Centre​

Permission NameDescriptionScope Reference
Command Centre AccessAccess Command Centre.CommandCentreAccess

Data Migration​

Permission NameDescriptionScope Reference
Data Migration AdministratorPerform data migrations using the legacy capability (broadly replaced by ETL).DataMigrationAdministrator

Data Protection​

Dashboards​

Permission NameDescriptionScope Reference
Data Protection Dashboard AccessAccess Data Protection dashboard, where actioned or matched Orphan entities will be displayed.DataProtectionDashboardAccess

Configuration​

Permission NameDescriptionScope Reference
Data Protection Configuration AccessAccess Data Protection Configuration, such as Data Protection Regimes and the Entity Check rule.DataProtectionAccess
Data Protection Configuration CreateCreate Data Protection Regimes, feature toggles and Entity Check rule configuration.DataProtectionCreate
Data Protection Configuration EditEdit Data Protection Configuration.DataProtectionEdit
Data Protection Configuration ApproveApprove Data Protection Configuration.DataProtectionApprove
Data Protection Configuration ArchiveArchive Data Protection Configuration.DataProtectionArchive
Data Protection Configuration DeleteDelete Data Protection Configuration.DataProtectionDelete
Data Protection Automatic Re-Onboarding EditUpdate Automatic Re-Onboarding toggle.DataProtectionAutomaticReOnboardingEdit
Permission NameDescriptionScope Reference
Legal Hold AccessView Legal Hold details and status on an Entity Profile and receive Legal Hold expiry notifications when eligible.LegalHoldAccess
Legal Hold EditCreate and modify a Legal Hold on an entity, including its reason, details, duration and Responsible Team.LegalHoldEdit
Legal Hold DeleteRemove an existing Legal Hold from an entity, allowing the entity to return to the standard deletion lifecycle.LegalHoldDelete

Digital Agents​

Central Agent Configuration​

Permission NameDescriptionScope Reference
Kyra AccessSee and interact with Kyra.KyraAccess
Agent Configuration AccessAccess Agent configuration.AgentConfigurationAccess
Agent Configuration EditEdit Agent configuration.AgentConfigurationEdit
Agent Governance AccessAccess digital agent metrics in the command centre, and agent rationale on the journey hub.DigitalAgentsAccess

Significance Rules​

Permission NameDescriptionScope Reference
Significance Task AccessAccess, edit and complete the Significance Tasks.SignificanceTaskAccess
Significance Task EditOverwrite task-level significance outcomes and complete the Significance Task.SignificanceTaskEdit
Significance Rule AccessAccess the Significance Rules.SignificanceRuleAccess
Significance Rule EditAdd and edit existing configuration.SignificanceRuleEdit
Significance Rule DeleteDelete existing configuration.SignificanceRuleDelete

Policy Agent​

Permission NameDescriptionScope Reference
Policy Agent AccessAccess Policy Agent.PolicyAgentAccess
Policy Agent EditEdit Policy Agent.PolicyAgentEdit
Policy Agent ApproveApprove Policy Agent changes.PolicyAgentApprove
Policy Agent DeleteDelete Policy Agent activities.PolicyAgentDelete

Document Agent​

Permission NameDescriptionScope Reference
Document Agent Managed Knowledge Base AccessAccess the Managed Knowledge Base used by the Document Agent.IdpRagAccess
Document Agent Managed Knowledge Base EditAdd new Knowledge Base entries or edit existing ones.IdpRagEdit
Document Agent Managed Knowledge Base DeleteDelete existing resource.IdpRagDelete

Digital ID&V​

Permission NameDescriptionScope Reference
Digital ID&V AccessProvides access to Digital ID&V functionality and verification information within Fenergo SaaS. This includes viewing Digital ID&V information associated with individuals and accessing ID&V results presented for review as part of the Digital ID&V process.DigitalIdvAccess
Digital ID&V CreateAllows users to initiate a Digital ID&V request through Jumio by generating a unique Jumio verification link for an individual. The link can be provided to the individual to complete the identity verification process, with the resulting status tracked in Fenergo SaaSDigitalIdvCreate
Digital ID&V ConfigurationAllows users to configure Digital ID&V within Fenergo SaaS, including creating and managing Identity Verification Configurations for the Fenergo SaaS Digital ID&V solution, as well as connecting, configuring, and enabling or disabling supported external Digital ID&V providersDigitalIdvConfiguration
Digital ID&V Approve Or RejectAllows users to approve or reject completed Digital ID&V results during the ID&V review process. Users can select the applicable approval or rejection reason and capture a supporting comment where requiredApproveOrReject

ID&V​

Permission NameDescriptionScope Reference
ID&V AccessAllows a user to access the Related Party Data & Documents task in order to complete the additional data and document capture that forms ID&V.IdvAccess
ID&V EditAllows a user to edit the fields within the Related Party Data & Documents task to complete the in-scope requirements.IdvEdit
ID&V DeleteAbility to bring an entity out of scope for ID&V in a journey.IdvDelete
ID&V Add ScopeAllows a user access to the grid option to add an associated Related Party to the scope of the task.IdvAddScope
ID&V Remove ScopeAllows a user access to the grid option to remove one or more selected related parties from the scope of the task. This does not remove the entity from the hierarchy and does not delete the entity draft should any changes have been made.IdvRemoveScope
ID&V Configuration AccessAllows a user to interact with and navigate into the Related Party Scoping Rules option under the Management Menu for Journey. Note: Journey Access is required to see this menu option.IdvConfigurationAccess
ID&V Configuration CreateAllows a user to create a Related Party Scoping Rule or clone an existing Related Party Scoping Rule set.IdvConfigurationCreate
ID&V Configuration EditAllows a user to create a new version of an existing Related Party Scoping Rule set, update an existing draft version of a Related Party Scoping Rule set, or submit an existing Related Party Scoping Rule set draft version for approval.IdvConfigurationEdit
ID&V Configuration ApproveAllows a user to approve or reject a version of a Related Party Scoping Rule set which has been submitted for approval.IdvConfigurationApprove
ID&V Configuration ArchiveAllows a user to archive a version of a Related Party Scoping Rule set.IdvConfigurationArchive
ID&V Configuration DeleteAllows a user to delete an existing Related Party Scoping Rule set and all its versions and delete the selected version of an existing Related Party Scoping Rule set.IdvConfigurationDelete

Document Management​

Permission NameDescriptionScope Reference
Document Management AccessView documents associated with an entity. Required by all users who need to open the Documents tab for an entity, view document metadata, and use the document viewer.DocumentManagementAccess
Document Management CreateUpload new documents, populate document metadata, and submit requirements for approval, waive or deferral. Required by users who add documents to an entity.DocumentManagementCreate
Document Management Create VirtualCreate virtual document management models.DocumentManagementCreateVirtual
Document Management EditEdit the metadata of an existing document.DocumentManagementEdit
Document Management ApproveApprove or reject document requirements. Allows approval of requirements with a status of Pending Approval, and rejection of requirements marked Waive Requested or Deferral Requested.DocumentManagementApprove
Document Management - ArchiveArchive documents on the entity profile page. Displays the archive control on the Documents tab. Unarchiving requires the separate Document Management - Unarchive permission.DocumentManagementArchiveV2
Document Management - UnarchiveUnarchive documents on the entity profile page. Archiving requires the separate Document Management - Archive permission.DocumentManagementUnarchive
Document Management DeleteDelete a document that has previously been uploaded.DocumentManagementDelete
Document Management Apply To AllBulk actions applied to multiple selected Documents.DocumentManagementApplyToAll
Document Management Defer or WaiveApprove document requirements with a status of Waive Requested or Deferral Requested. Note that rejecting requirements in these states additionally requires Document Management Approve.DocumentManagementDeferOrWaive
Document Management LinkLink or reuse an existing document against a requirement without needing document create permissions.DocumentManagementLink
Document Management Send for SignatureRequest eSignature for a document requirement. Should not be granted where eSignature is not enabled for the tenant.DocumentManagementSendForSignature

Document Types and Metadata Configuration​

Permission NameDescriptionScope Reference
Document Configuration AccessAccess and view Document Types and Document Requirement Metadata configuration under Reference Data.DocumentConfigurationAccess
Document Configuration EditCreate and update Document Type and Document Requirement Metadata configuration sets and their draft versions.DocumentConfigurationEdit
Document Configuration ApproveApprove or reject Document Type and Document Requirement Metadata configuration versions submitted for approval.DocumentConfigurationApprove
Document Configuration ArchiveArchive a version of a Document Type or Document Requirement Metadata configuration set.DocumentConfigurationArchive
Document Configuration DeleteDelete versions of Document Type or Document Requirement Metadata configuration sets.DocumentConfigurationDelete

Document Generation​

Permission NameDescriptionScope Reference
Document Generation Configuration AccessAccess and view Document Generation configuration, including naming conventions, the Component Library and document templates.DocGenConfigurationAccess
Document Generation Configuration CreateCreate new Document Generation configuration sets, including naming conventions, component libraries and document templates.DocGenConfigurationCreate
Document Generation Configuration EditCreate new draft versions and modify Document Generation configuration, including components, mappings and templates, and submit versions for approval.DocGenConfigurationEdit
Document Generation Configuration ApproveApprove or reject Document Generation configuration versions submitted for approval.DocGenConfigurationApprove
Document Generation Configuration ArchiveArchive a Document Generation configuration version.DocGenConfigurationArchive
Document Generation Configuration DeleteDelete Document Generation configuration sets and their versions.DocGenConfigurationDelete

eSignature​

Permission NameDescriptionScope Reference
eSignature Configurator AccessAccess and view eSignature provider configuration, including connection and signature settings.ESignatureConfigurationAccess
eSignature Configurator CreateCreate eSignature configuration.ESignatureConfigurationCreate
eSignature Configurator EditEdit eSignature configuration.ESignatureConfigurationEdit
eSignature Configurator DeleteDelete eSignature configuration.ESignatureConfigurationDelete

Entity Data​

Permission NameDescriptionScope Reference
Change Entity Draft Access LayersChange the Access Layers assigned to an entity draft; changes are propagated to the related entity.EntityDataChangeEntityDraftAccessLayers
Entity Data Access & SearchSearch for and access entity and entity draft records, subject to the user's Access Layers. Baseline permission for users who need to find and open entity records.EntityDataAccessAndSearch
Entity Data EditCreate and update entity draft records, including entity data maintained through Journey tasks or supported APIs.EntityDataEdit
Entity Data ApproveVerify or reject entity drafts, allowing approved draft changes to become verified entity data. Required for users responsible for approving entity data changes.EntityDataApprove

Entity Profile​

Permission NameDescriptionScope Reference
Entity Profile ExportExport information from the Entity Profile for printing or saving as PDF, including entity data, Journeys, Related Parties, Products, Documents, Policies and Access Layers.EntityProfileExport
Entity Profile Configuration AccessAccess and view Legal Entity Profile Configuration, including configuration defined for each Legal Entity Type and common profile settings.EntityProfileConfigurationAccess
Entity Profile Configuration EditModify Legal Entity Profile Configuration, including the Overview details category, visibility and ordering of Policy Categories, hidden statuses and common profile settings.EntityProfileConfigurationEdit

New Entity Flow​

Permission NameDescriptionScope Reference
New Entity Configuration AccessAccess the configuration that guides the flow when a new entity is created.NewEntityConfigurationAccess
New Entity Configuration EditEdit the configuration that guides the flow when a new entity is created.NewEntityConfigurationEdit

Entity Group Management​

Permission NameDescriptionScope Reference
Entity Group Management Access & SearchSearch and access entity group records. Required by users who need to view Legal Entity Group records.EntityGroupManagementAccessAndSearch
Shared Data Template AccessAccess the Shared Data Template configuration area. Required before any other Shared Data Template permissions can be used.SharedDataTemplateAccess
Entity Group Management EditCreate and edit entity group records. Required by users responsible for maintaining Legal Entity Groups.EntityGroupManagementEdit
Shared Data Template CreateCreate new draft versions of Shared Data Templates that define the data, documents and Related Parties that can be shared within Legal Entity Groups.SharedDataTemplateCreate
Shared Data Template EditModify existing draft versions of Shared Data Templates.SharedDataTemplateEdit
Shared Data Template ApproveApprove draft Shared Data Template versions for publication and use within Legal Entity Groups.SharedDataTemplateApprove
Shared Data Template ArchiveArchive published versions of Shared Data Templates.SharedDataTemplateArchive
Shared Data Template DeleteDelete draft versions of Shared Data Templates.SharedDataTemplateDelete

ETL (Extract, Transform, Load)​

ETL​

Permission NameDescriptionScope Reference
ETL administratorAccess the ETL feature to configure and manage extract, transform and load operations.ETLAdministrator

Agency Migration​

Permission NameDescriptionScope Reference
ETL Agency Migration AdministratorAccess ETL Agency Migration projects to manage the migration of Agency objects (IM, UP, MR, Managed Products).AgencyMigrationETLAdministrator

Agency Bulk Upload​

Permission NameDescriptionScope Reference
Agency Request ETL administratorAccess and complete Agency ETL tasks to bulk upload UP, MR and Product data within an Agency Request journey.AgencyETLAdministrator

Events​

Event Ingress​

Permission NameDescriptionScope Reference
Get Event DetailsGet details of specific ingress event.EventIngressGetEventDetails
Get Event PayloadGet payload of specific ingress event.EventIngressGetEventPayload

Event Notifications​

Permission NameDescriptionScope Reference
Webhook AccessAccess webhook configuration.WebhookAccess
Webhook ManagementCreate/edit/delete webhook configurations.WebhookManagement

External Data Sources​

Permission NameDescriptionScope Reference
External Data AccessAccess External Data functionality within a Journey and initiate External Data searches against configured providers.ExternalDataAccess
External Data ApproveApprove the import of new Related Parties through External Data-related review activities.ExternalDataApprove
External Data Configurator AccessAccess and view External Data provider configuration.ExternalDataConfiguratorAccess
External Data Configurator CreateCreate and configure new custom External Data providers.ExternalDataConfiguratorCreate
External Data Configurator EditModify existing External Data provider configuration.ExternalDataConfiguratorEdit
External Data Configurator DeleteDelete a custom External Data provider and its configuration.ExternalDataConfiguratorDelete
External Data Mapper AccessAccess and view mappings between External Data providers and Fenergo Policy.ExternalDataMapperAccess
External Data Mapper EditCreate, modify and delete mappings between External Data provider data and Fenergo Policy.ExternalDataMapperEdit

Fenergo Portal​

Permission NameDescriptionScope Reference
Portal Administration User DeleteRemove portal users. Held separately from Portal User Administration so that removal can be restricted.PortalTenantUserAdminDelete
Portal Configuration AccessAccess the Portal Configuration area, covering portal details, appearance, footer and email settings.PortalTenantAccess
Portal Configuration EditUpdate the Portal Configuration, including portal details, appearance, footer and email settings.PortalTenantEdit
Portal User AdministrationAdd portal users, assign roles and link entities to them. Also grants access to the Portal Quick Link task.PortalTenantUserAdmin
Portal User Dashboard AccessView the portal dashboard configuration. Dashboards are assigned per portal role.DashboardAccess
Portal User Dashboard EditCreate and update portal dashboards.DashboardEdit
Portal User Role AccessView the details of the portal user roles configured for the tenant. Roles control which dashboards and business context a portal user can see; a portal user may hold up to five roles.UserRoleAccess
Portal User Role ConfigurationCreate and update portal user role configuration.UserRoleConfiguration
Portal User Role DeleteDelete portal user roles.UserRoleDelete
Quick Link AccessView the portal users currently linked to an entity from the Portal Quick Link task, along with their status, relationship, email address and portal role.QuickLinkAccess
Quick Link EditLink and unlink portal users on an entity from the Portal Quick Link task.QuickLinkEdit
Domain Verification EditManage email domain (add, verify, enable).EmailDomainVerify

Integration Flows​

Configuration​

Permission NameDescriptionScope Reference
Auth Configuration AccessAccess the authentication configurations used by integration flows to connect to external systems.IntegrationFlowsAuthConfigurationAccess
Auth Configuration EditCreate and edit the authentication configurations used by integration flows.IntegrationFlowsAuthConfigurationEdit
Configuration AccessAccess integration flow configurations in Flow Studio.IntegrationFlowsConfigurationAccess
Configuration EditCreate and edit integration flow configurations in Flow Studio.IntegrationFlowsConfigurationEdit
Configuration ApproveApprove an integration flow configuration for publication.IntegrationFlowsConfigurationApprove
Configuration DeleteDelete an integration flow configuration.IntegrationFlowsConfigurationDelete

Flow Interactions​

Permission NameDescriptionScope Reference
Flow API TriggerTrigger an integration flow directly from its API endpoint, rather than from a scheduled or event-based trigger.IntegrationFlowsFlowApiTrigger
Flow Debug DraftDebug a draft flow, or re-run a flow in debug mode from the Execution Details view.IntegrationFlowsTestExecution
Flow Debug Transformer TaskDebug the code inside a Transformer task. Grants visibility of data passing through the transformer, so it should be granted with the same care as access to the underlying data.IntegrationFlowsTestTransformerTask
Flow Execution Details ReadView the step-level logs for a flow execution. Required to diagnose where and why a flow failed.IntegrationFlowsFlowExecutionDetailsRead
Flow Execution ReadView the record of integration flow executions, including their status and history.IntegrationFlowsFlowExecutionRead
Flow Execution RetryRe-run a failed or incomplete integration flow execution.IntegrationFlowsFlowExecutionRetry
Flow Task CloseClose or complete an Integrations Data Publish task within a journey, allowing the journey to progress where the integration cannot be completed successfully.IntegrationFlowsFlowTaskClose
Flow Task RetryRetry a failed Integrations Data Publish task from within a journey.IntegrationFlowsFlowTaskRetry
Mapping EditEdit the data mapping configurations used by integration flows.IntegrationFlowsMappingEdit

Persisted Storage​

Permission NameDescriptionScope Reference
Persisted Storage AccessProvides read access to the list of files held in Persisted Storage as a paginated view in Flow Studio.IntegrationFlowsPersistedStorageAccess
Persisted Storage Delete RecordDelete a file from Persisted Storage before its time-to-live expires.IntegrationFlowsPersistedStorageDelete
Persisted Storage Get RecordView the contents of a non-sensitive file in Persisted Storage. Needed alongside Persisted Storage Access to inspect file content when debugging or reviewing a flow.IntegrationFlowsPersistedStorageGet
Persisted Storage Get Sensitive RecordView the contents of a file marked as Sensitive in Persisted Storage. Held separately from the standard get permission so that files containing sensitive data can be restricted to a smaller group of users.IntegrationFlowsPersistedStorageGetSensitive

Logging Centre APIs​

Permission NameDescriptionScope Reference
Logging Centre AccessAccess logs produced by Fenergo SaaS integration services, including checking logging status, searching for logs and retrieving log results.LoggingCentreAccess
Logging Centre EditChange Logging Centre settings, including opting integration logging in or out.LoggingCentreEdit

Investment Account Management​

Bank Accounts​

Permission NameDescriptionScope Reference
Delete Verified Bank Account RelationshipsDelete the relationship between a verified bank account and an investor.TransferAgencyDeleteVerifiedBankAccountRelationships

Account Control Configuration​

Permission NameDescriptionScope Reference
Account Control Configuration AccessAccess and view the tenant-wide Account Control Configuration settings for Investment Accounts. Settings are read-only without Edit permission.AccountControlConfigurationAccess
Account Control Configuration EditModify and save tenant-wide Account Control Configuration settings that control Investment Account behaviour.AccountControlConfigurationEdit

ISDA Amend​

Permission NameDescriptionScope Reference
Isda AccessAccess the ISDA Amend configuration area. This permission is required in addition to ISDA Configuration.IsdaAccess
Isda ConfigurationConfigure ISDA Amend, including S&P connection credentials, protocol activation and mappings to Policy, and ISDA scheduler frequency. This permission is required together with Isda Access to enter the configuration area.IsdaConfiguration

Journey Management​

Journeys​

Permission NameDescriptionScope Reference
Journey AccessView Journey instances assigned to the user's team in Journey Hub.JourneyAccess
Change Journey Access LayersChange the Access Layers assigned to a Journey instance, controlling which users can access that Journey.JourneyChangeAccessLayers
Completed Task AccessView a completed task, even when the user is not a member of the tasks assigned team.JourneyCompletedTaskAccess
Journey CreateCreate or launch new Journey instances.JourneyCreate
Journey EditProgress an in-flight Journey by completing tasks and submitting review outcomes; this is operational Journey access rather than Journey configuration.JourneyEdit
Journey CancelCancel an in-flight Journey instance.JourneyCancel
Journey Pause InstancePause or resume an entire Journey instance, including its stages and tasks with SLA configuration.JourneyPauseInstance
Journey Pause StagePause or resume an individual Journey stage and its tasks with SLA configuration.JourneyPauseStage
Journey Pause TaskPause or resume an individual in-progress Journey task.JourneyPauseTask
Journey Reassign Read Only TaskAssign or change the teams that have read-only access to a Journey task.JourneyReassignReadOnlyTask
Journey Reassign Task Owner & TeamReassign both the Team and Owner of a Journey task when the user has access to the task's currently assigned Team.JourneyReassignTask
Journey Reassign Task Owner OnlyReassign the Owner of a Journey task while leaving its assigned Team unchanged; access to the currently assigned Team is required.JourneyReassignTaskOwnerOnly
Journey Reassign Task Owner, No Task AccessReassign a task where the user does not have access to its currently assigned Team, including tasks that are sealed because their assigned Team is unavailable or inaccessible.JourneyReassignOwnerNoTaskAccess
Journey Reopen TaskReopen a completed Journey task so that the workflow can return to that task for further work.JourneyReopenTask
Reassign Journey Owner and TeamChange both the Journey Owner and the Owner's Team for a Journey.JourneyOwnerEdit
Reassign Journey Owner OnlyChange the Journey Owner while leaving the Owner's Team unchanged.JourneyOwnerEditOwnerOnly
Set Journey StateSet or change the configurable State assigned to a Journey instance from Journey Hub.JourneyCustomStatusEdit
SLA Working Days Configuration AccessAccess and view the SLA Configuration settings that define working days and the reference timezone used for Journey SLA calculations.WorkingDaysAccess
SLA Working Days Configuration EditModify and save the working days and reference timezone used when calculating Journey, Stage and Task SLAs.WorkingDaysEdit
Unassign Journey or Task OwnerClear the assigned Journey Owner or Task Owner without assigning a replacement, while retaining the existing Team assignment.JourneyUnassignOwner

Journey Builder​

Permission NameDescriptionScope Reference
Journey Builder AccessAccess and view Journey definitions and their configuration in Journey Builder.JourneyBuilderAccess
Journey Builder EditCreate and modify Journey definitions, including creating Journey schemas and versions, editing draft or rejected versions, cloning versions and submitting changes for approval.JourneyBuilderEdit
Journey Builder ApproveApprove or reject Journey definition versions submitted for approval.JourneyBuilderApprove
Journey Builder ArchiveArchive a Journey definition version.JourneyBuilderArchive
Journey Builder DeleteDelete a Journey definition version or the complete Journey definition and all its versions.JourneyBuilderDelete
Journey Launch Control AccessAccess and view Journey Launch Controls that define when Journey Types can or cannot be initiated.JourneyLaunchControlsAccess
Journey Launch Control EditCreate and modify Journey Launch Controls, including conditions and team restrictions that determine whether a Journey Type can be launched.JourneyLaunchControlsEdit
Journey Launch Control DeleteDelete configured Journey Launch Controls.JourneyLaunchControlsDelete

Journey Configuration Drawer​

Permission NameDescriptionScope Reference
Journey Configuration EditModify Journey configuration settings and toggles. Typically granted to System Configuration users in lower-level environments and not typically granted in Production.JourneyConfigurationEdit

Journey Scheduler​

Permission NameDescriptionScope Reference
Journey Scheduler AccessAccess and view Journey Scheduler and configured Journey Schedules.JourneySchedulerAccess
Journey Scheduler EditCreate and modify Journey Schedules, including schedule versions, draft or rejected versions, clones and schedule dates.JourneySchedulerEdit
Journey Scheduler ApproveSubmit Journey Schedule versions for approval and approve or reject submitted versions.JourneySchedulerApprove
Journey Scheduler ArchiveArchive a Journey Schedule version.JourneySchedulerArchive
Journey Scheduler DeleteDelete Journey Schedule versions, complete Journey Schedules and Journey Schedule date records.JourneySchedulerDelete
Journey Scheduler TriggerTrigger the scheduler via its endpoint (vs waiting for the daily scheduled run). This is not usually granted to users in a live tenant, but rather used to accelerate testing.JourneySchedulerTrigger

Loan Origination​

Financial Analysis​

Permission NameDescriptionScope Reference
Financial Analysis Report AccessDownload the completed Financial Analysis task data as a CSV report reflecting the financial data currently displayed for the selected entity or deal.FinancialAnalysisReport
Financial Analysis AccessAccess and view Financial Analysis and Capacity to Service records, versions and associated data within the relevant Journey context.FinancialAnalysisAccess
Financial Analysis EditCreate and update Financial Analysis and Capacity to Service records and versions, including financial data, scenarios, summaries and completion status.FinancialAnalysisEdit
Financial Analysis Configuration AccessAccess and view Financial Analysis configurations and their versions.FinancialAnalysisConfigurationAccess
Financial Analysis Configuration CreateCreate new Financial Analysis configurations and create new draft versions of existing configurations, including submitting configuration versions for approval.FinancialAnalysisConfigurationCreate
Financial Analysis Configuration EditModify draft or rejected Financial Analysis configuration versions and clone existing configuration versions.FinancialAnalysisConfigurationEdit
Financial Analysis Configuration ApproveApprove or reject Financial Analysis configuration versions submitted for approval.FinancialAnalysisConfigurationApprove
Financial Analysis Configuration ArchiveArchive a Financial Analysis configuration version.FinancialAnalysisConfigurationArchive
Financial Analysis Configuration DeleteDelete a Financial Analysis configuration and all of its versions.FinancialAnalysisConfigurationDelete
Financial Analysis Import Configuration AccessAccess and view Financial Analysis Import providers and their configuration, mappings and adapter schemas.FinancialImportProviderAccess
Financial Analysis Import Configuration CreateCreate Financial Analysis Import provider configuration components, including provider mappings and adapter schemas.FinancialImportProviderCreate
Financial Analysis Import Configuration EditModify Financial Analysis Import providers, mappings and adapter schemas, including enabling or disabling an import provider.FinancialImportProviderEdit
Financial Analysis Import Configuration DeleteDelete Financial Analysis Import provider configuration components, including provider mappings and adapter schemas.FinancialImportProviderDelete

Capacity to Service​

Permission NameDescriptionScope Reference
Capacity to Service Configuration AccessAccess and view Capacity to Service configurations and their versions.AllocationConfigurationAccess
Capacity to Service Configuration CreateCreate new Capacity to Service configurations and create new draft versions of existing configurations.AllocationConfigurationCreate
Capacity to Service Configuration EditModify draft or rejected Capacity to Service configuration versions and clone existing configuration versions.AllocationConfigurationEdit
Capacity to Service Configuration ApproveApprove or reject Capacity to Service configuration versions submitted for approval.AllocationConfigurationApprove
Capacity to Service Configuration ArchiveArchive a Capacity to Service configuration version.AllocationConfigurationArchive
Capacity to Service Configuration DeleteDelete a Capacity to Service configuration and all of its versions.AllocationConfigurationDelete

Credit Screening​

Permission NameDescriptionScope Reference
Automated Credit Screening AccessAccess and view automated Credit Screening enquiries and outcomes returned by configured screening providers. This permission is also accepted by the APIs for viewing Credit Screening provider configuration.CreditScreeningAccess
Automated Credit Screening DeleteDelete automated Credit Screening enquiries. The same permission is also accepted by the APIs for deleting Credit Screening providers and associated provider configuration, mappings and adapter schemas.CreditScreeningDelete
Manual Credit Screening AccessAccess and view Manual Credit Screening records, versions and screening history captured for entities within Journeys.ManualCreditScreeningAccess
Manual Credit Screening CreateCreate a new Manual Credit Screening record and its initial draft version for an entity within a Journey task.ManualCreditScreeningCreate
Manual Credit Screening EditCreate new versions and update, complete or reject draft Manual Credit Screening records, including capturing manually sourced screening information.ManualCreditScreeningEdit

Credit Assessment​

Permission NameDescriptionScope Reference
Automated Credit Assessment AccessAccess and view automated Credit Assessment enquiries and outcomes returned by configured assessment providers. This permission is also accepted by the APIs for viewing Credit Assessment provider configuration.AutomatedCreditAssessmentAccess
Automated Credit Assessment DeleteDelete automated Credit Assessment enquiries. The same permission is also accepted by the APIs for deleting Credit Assessment providers and associated provider configuration, mappings and adapter schemas.AutomatedCreditAssessmentDelete
Manual Credit Assessment AccessAccess and view Manual Credit Assessment records, versions and assessment history captured within Journeys.CreditAssessmentAccess
Manual Credit Assessment EditCreate and update Manual Credit Assessment records and draft versions, including capturing assessment decisions and completing assessments within a Journey.CreditAssessmentEdit
Manual Credit Assessment DeleteDelete a Manual Credit Assessment set and all assessments contained within it.CreditAssessmentDelete

Credit Data Sources​

Permission NameDescriptionScope Reference
Credit Assessment Configuration AccessAccess and view automated Credit Assessment providers and their provider configuration, mappings, adapter schemas and configuration status.CreditAssessmentConfigurationAccess
Credit Assessment Configuration CreateCreate automated Credit Assessment providers and associated provider configuration, mappings and adapter schemas.CreditAssessmentConfigurationCreate
Credit Assessment Configuration EditModify automated Credit Assessment providers, provider configuration, mappings and adapter schemas, including enabling or disabling a provider.CreditAssessmentConfigurationEdit
Credit Assessment Configuration DeleteDelete automated Credit Assessment providers and associated provider configuration, mappings and adapter schemas.CreditAssessmentConfigurationDelete
Credit Screening Configuration AccessAccess and view Credit Screening providers and their provider configuration, mappings, adapter schemas and configuration status.CreditScreeningDataSourcesAccess
Credit Screening Configuration CreateCreate Credit Screening providers and associated provider configuration, mappings and adapter schemas.CreditScreeningDataSourcesCreate
Credit Screening Configuration EditModify Credit Screening providers, provider configuration, mappings and adapter schemas, including enabling or disabling a provider.CreditScreeningDataSourcesEdit
Credit Screening Configuration DeleteDelete Credit Screening providers and associated provider configuration, mappings and adapter schemas.CreditScreeningDataSourcesDelete

Credit Policy Configuration​

Permission NameDescriptionScope Reference
Credit Policy Configuration AccessAccess and view configurations within the Credit Policy feature.CreditPolicyAccess
Credit Policy Configuration EditCreate new and modify existing Credit Policy configuration versions.CreditPolicyEdit
Credit Policy Configuration ApproveApprove Credit Policy configuration versions.CreditPolicyApprove
Credit Policy Configuration ArchiveArchive Credit Policy configuration versions.CreditPolicyArchive
Credit Policy Configuration DeleteDelete draft Credit Policy configuration versions.CreditPolicyDelete

Collateral Management​

Permission NameDescriptionScope Reference
Collateral AccessAccess Collateral and Asset records and drafts, including Journey-specific collateral data and related collateral.CollateralAccess
Collateral Access and SearchAccess, search and retrieve Collateral and Asset records and drafts, including Journey-specific collateral data and related collateral.CollateralAccessAndSearch
Collateral EditCreate and update Collateral and Asset records and drafts within a Journey, including deleting unverified drafts.CollateralEdit
Collateral VerificationAllows API command to verify collateral (same operation as the Verify Collateral task).CollateralVerification
Collateral ApproveVerify Collateral and Asset drafts so that draft information is merged into the verified Collateral or Asset record.CollateralApprove

Covenants and Conditions​

Permission NameDescriptionScope Reference
Covenants & Conditions AccessAccess and view Covenants & Conditions sets and their versions for a Deal.CovenantsConditionsAccess
Covenants & Conditions EditCreate and update Covenants & Conditions sets and draft versions, including completing and verifying Covenants & Conditions versions within a Journey.CovenantsConditionsEdit

Calculated Fields​

Permission NameDescriptionScope Reference
Calculation Configuration AccessAccess and view Calculation Configuration and existing formulas used by Calculated Fields.CalculationEngineAccess
Calculation Configuration CreateCreate new calculation formulas, including defining formula names, descriptions, data sources and formula elements.CalculationEngineCreate
Calculation Configuration EditModify calculation formulas using the formula builder, including operators, datakeys, values, functions and data sources.CalculationEngineEdit
Calculation Configuration ApproveApprove calculation formula configurations for publication.CalculationEngineApprove
Calculation Configuration ArchiveArchive calculation formula configurations.CalculationEngineArchive
Calculation Configuration DeleteDelete calculation formula configurations.CalculationEngineDelete

Localisation​

Permission NameDescriptionScope Reference
Localisation AccessAccess and view Localisation configuration, including tenant language packs, versions, supported languages and translation contexts.LocalisationAccess
Localisation EditCreate and modify Localisation language packs and draft versions, including translation contexts and files, and submit versions for approval.LocalisationEdit
Localisation ApproveApprove or reject Localisation versions submitted for approval.LocalisationApprove
Localisation ArchiveArchive an existing Localisation version.LocalisationArchive
Localisation DeleteDelete Localisation versions, complete Localisations and their versions, or individual Localisation contexts.LocalisationDelete

Narratives​

Permission NameDescriptionScope Reference
Narratives AccessAccess the Narratives tab on the entity profile page. Required before any individual narrative category permission takes effect.NarrativesAccess
Business Narratives AccessView business narratives on the Narratives tab.NarrativesBusinessAccess
Business Narratives CreateAdd new business narratives. Displays the Add control for the Business Narratives category.NarrativesBusinessCreate
Business Narratives EditEdit existing business narratives.NarrativesBusinessEdit
Business Narratives DeleteDelete business narratives.NarrativesBusinessDelete
Compliance Narratives AccessView compliance narratives on the Narratives tab.NarrativesComplianceAccess
Compliance Narratives CreateAdd new compliance narratives. Displays the Add control for the Compliance Narratives category.NarrativesComplianceCreate
Compliance Narratives EditEdit existing compliance narratives.NarrativesComplianceEdit
Compliance Narratives DeleteDelete compliance narratives.NarrativesComplianceDelete

Policy​

Policy Configuration​

Permission NameDescriptionScope Reference
Policy Configuration AccessAccess the Policy Configuration feature. Typically granted to System Configuration users in lower-level environments, and generally only to Application Support Teams in Production.PolicyConfigurationAccess
Policy Configuration EditCreate and modify policy configuration. Typically withheld from users in Production.PolicyConfigurationEdit
Policy Configuration ApprovalApprove a policy configuration version for publication. Typically withheld from users in Production.PolicyConfigurationApprove
Policy Configuration ArchiveArchive within the Policy Config.PolicyConfigurationArchive
Policy Configuration DeleteDelete within the Policy Config.PolicyConfigurationDelete
Policy Workspace Configuration AccessAccess Policy v2 Workspaces.PolicyWorkspaceConfigurationAccess
Policy Workspace Configuration EditInteract with the Policy v2 Workspace Config (e.g. Edit).PolicyWorkspaceConfigurationEdit
Permission NameDescriptionScope Reference
Policy Search and Requirement ScopeSearch Policy and retrieve or evaluate the Policy requirements that are in scope for a given entity or Journey context.PolicySearch

Policy Simulator​

Permission NameDescriptionScope Reference
Policy Simulator AccessPolicy Simulator is used to test and validate Policy configuration behaviour before publication.PolicySimulatorAccess

Product Enablement​

Product Task and Journey interactions​

Permission NameDescriptionScope Reference
Product Access & SearchSearch for and access Product records within Fenergo SaaS.ProductAccessAndSearch
Product EditCreate and edit Product draft records within a Journey, including maintaining Product data before verification.ProductEdit
Product ApproveRequired to invoke the Verify Product Draft command endpoint, which publishes Product changes captured in a draft (via a Journey or otherwise) to the verified Product record.ProductApprove
Product Conflict Resolution AccessView Product conflicts within the Products tab of a Conflict Resolution task in a Journey.ProductConflictResolutionAccess
Product Conflict Resolution EditResolve Product conflicts by selecting which conflicting values to retain in the Product draft. Requires Product Conflict Resolution Access and Product Edit.ProductConflictResolutionEdit
Product OffboardingOffboard an active Product or re-onboard an offboarded Product within a Journey, creating a draft that is finalized through Product verification.ProductOffboard
Product Proposed Changes AccessView Product changes within the Products tab of a Proposed Changes task in a Journey.ProductProposedChangesAccess
Product Proposed Changes EditResolve proposed Product changes by selecting which values to retain in the verified Product. Requires Product Proposed Changes Access and Product Edit.ProductProposedChangesEdit
Product Requirement ScopeView and interact with Product-scoped data and document requirements presented within Journey tasks.ProductConfigurationSearch

Product Configuration​

Permission NameDescriptionScope Reference
Product Configuration AccessAccess and view Product Configuration and Product Requirement Sets.ProductConfigurationAccess
Product Configuration EditCreate Product Requirement Sets, modify draft versions and submit drafts for approval.ProductConfigurationEdit
Product Configuration ApprovalApprove Product Requirement Set versions submitted for publication.ProductConfigurationApprove
Product Configuration ArchiveArchive a Product Requirement Set version.ProductConfigurationArchive
Product Configuration DeleteDelete a Product Requirement Set version or the complete Product Requirement Set record.ProductConfigurationDelete

Deals​

Permission NameDescriptionScope Reference
Deal Access and SearchSearch for and access Deal records, including Deal information available within the context of a Journey.DealAccessAndSearch
Deal CreateCreate new Deals and associated Deal drafts for capture within a Journey.DealCreate
Deal EditEdit Deal draft records within a Journey, including creating the drafts required to update an existing verified Deal.DealEdit
Deal ApproveAbility to approve a deal within the Manage Deals task.DealApprove
Deal DeleteDelete Deals or Deal drafts captured in error before the Deal has been verified. Verified Deals cannot be deleted.DealDelete
Deal Requirement ScopeView and interact with Deal requirements that are in scope within a Journey.DealRequirementScope

Deal Configuration​

Permission NameDescriptionScope Reference
Deal Configuration AccessAccess and view Deal Configuration and configured Deal Requirement Sets.DealConfigurationAccess
Deal Configuration EditCreate Deal Requirement Sets, create and modify draft versions, maintain requirements and submit versions for approval.DealConfigurationEdit
Deal Configuration ApproveApprove Deal Requirement Set versions submitted for publication.DealConfigurationApprove
Deal Configuration ArchiveArchive a Deal Requirement Set version.DealConfigurationArchive
Deal Configuration DeleteDelete Deal Requirement Set versions or complete Requirement Set records, including requirements within a configurable version.DealConfigurationDelete

Reference Data​

Permission NameDescriptionScope Reference
Lookup AccessInteract with Reference Data lookups used across the application. Required by users who need to use lookup-backed fields and is also required to interact with the Reference Data feature.LookupAccess
Reference Data Editor AccessAccess and view the Reference Data feature, including Reference Data lists and CSV download/upload functionality. Also requires Lookup Access.ReferenceDataEditorAccess
Reference Data Editor EditCreate new Reference Data lists and new draft versions, modify draft or rejected versions, add or remove values, import CSV updates and submit changes for approval. Also requires Lookup Access.ReferenceDataEditorEdit
Reference Data Editor ApproveApprove or reject Reference Data list versions submitted for approval.ReferenceDataEditorApprove
Reference Data Editor ArchiveArchive a Reference Data list version.ReferenceDataEditorArchive
Reference Data Editor DeleteDelete Reference Data lists and their versions, including linked lookup records and versions. System Lookups cannot be deleted.ReferenceDataEditorDelete
Permission NameDescriptionScope Reference
Association AccessView an entity's hierarchy and Related Parties, including association details. Does not permit association data to be edited.AssociationAccess
Association EditAdd new draft Related Party associations and edit existing draft associations within a Journey.AssociationEditOnly
Association VerificationVerify draft Related Party associations and resolve conflicts between draft and verified hierarchies.AssociationVerification
Association DeleteDelete draft associations or mark verified associations for removal through the association lifecycle.AssociationDeleteOnly
Association Edit & DeleteFully maintain Related Parties within the Hierarchy Capture task, including adding, editing and removing associations.AssociationEdit
Association Edit & Link OnlyAdd or edit Related Party associations by linking existing entities only; does not allow new entities to be created as part of the linking process.AssociationEditAndLinkOnly
Association Edit & Partial DeleteAdd, edit and remove Related Party associations, but prevents removal of all associations between the same source and target entities.AssociationEditAndPartialDelete

Review Manager​

Permission NameDescriptionScope Reference
Deferred Document Requirements Review Config AccessAccess and view the Document Requirements tab in Review Journey Scheduling configuration.DeferredDocRequirementsReviewConfigAccess
Deferred Document Requirements Review Config EditConfigure deferred Document Requirement reviews, including enabling or disabling the setting and selecting the Review Journey to launch.DeferredDocRequirementsReviewConfigEdit
Review Journey Scheduling AccessAccess and view the Scoping Rules used to determine Review Journey scheduling. Product Configuration Access is additionally required to view the Product Scoping Rules tab.ReviewJourneySchedulingAccess
Review Journey Scheduling EditCreate new Review Journey Scheduling Scoping Rules and save draft versions.ReviewJourneySchedulingEdit
Review Journey Scheduling ApproveSubmit draft Review Journey Scheduling Scoping Rules for approval and approve or reject submitted versions.ReviewJourneySchedulingApprove
Review Journey Scheduling ArchiveArchive published Review Journey Scheduling Scoping Rule versions.ReviewJourneySchedulingArchive
Review Journey Scheduling DeleteDelete Review Journey Scheduling Scoping Rule instances and draft versions.ReviewJourneySchedulingDelete
Review Manager AccessAccess the Review Manager dashboard from the main navigation.ReviewManagerAccess
Review Manager Configuration AccessAccess and view Review Manager dashboard configuration, including the configured dashboard columns.ReviewManagerConfigurationAccess
Review Manager Configuration EditModify Review Manager dashboard configuration, including the columns displayed on the dashboard.ReviewManagerConfigurationEdit
Scheduled Review AccessView an entity's Scheduled Reviews on the Entity Profile or through the Review Query API. Journey Access also provides visibility of Scheduled Reviews.ScheduledReviewAccess
Scheduled Review EditCreate and update Scheduled Review records.ScheduledReviewEdit
Scheduled Review DeleteDelete Scheduled Review records.ScheduledReviewDelete

Risk​

Risk Configuration​

Permission NameDescriptionScope Reference
Risk Calculator AccessAccess risk calculator.RiskCalculatorAccess
Risk Configuration AccessAccess the Risk Configuration feature. Typically granted to System Configuration users in lower-level environments, and generally only to Application Support Teams in Production.RiskConfigurationAccess
Risk Configuration EditCreate and modify risk configuration. Typically withheld from users in Production.RiskConfigurationEdit
Risk Configuration ApproveApprove or reject risk configuration models. Typically withheld from users in Production.RiskConfigurationApprove
Risk Configuration ArchiveArchive risk configuration models.RiskConfigurationArchive
Risk Configuration DeleteDelete risk configuration models.RiskConfigurationDelete

Risk Impact Assessment​

Permission NameDescriptionScope Reference
Risk Impact Assessment AccessAccess Risk Impact Assessments.RiskImpactAssessmentAccess
Risk Impact Assessment EditCreate and edit Risk Impact Assessments.RiskImpactAssessmentEdit

Screening​

Screening Task interactions​

Permission NameDescriptionScope Reference
Screening AccessAccess and view screening results, including match details, classifications and materiality assessments.ScreeningAccess
Screening CreateCreate a new screening batch to screen one or more entities against configured screening providers.ScreeningCreate
Screening EditReview and action screening results, including resolving matches, recording classifications or materiality assessments and completing screening batches.ScreeningEdit
Screening ApproveApprove or reject screening escalation tasks where this approval model is used.ScreeningApprove
Screening DeleteDelete an existing screening batch.ScreeningCancel

Screening Configuration​

Permission NameDescriptionScope Reference
Screening Configuration AccessAccess and view Screening configuration and configured Screening Scoping Rule Sets.ScreeningConfigurationAccess
Screening Configuration CreateCreate new Screening Scoping Rule Sets and their initial draft versions.ScreeningConfigurationCreate
Screening Configuration EditCreate new versions of existing Screening Scoping Rule Sets, modify draft versions and submit them for approval.ScreeningConfigurationEdit
Screening Configuration ApproveApprove or reject Screening Scoping Rule Set versions submitted for approval.ScreeningConfigurationApprove
Screening Configuration ArchiveArchive a Screening Scoping Rule Set version.ScreeningConfigurationArchive
Screening Configuration DeleteDelete a Screening Scoping Rule Set version or the complete Scoping Rule Set and all its versions.ScreeningConfigurationDelete

Support​

Permission NameDescriptionScope Reference
Intercom AccessEnables users to directly chat with Fenergo Support and raise support tickets.IntercomAccess

Transaction Monitoring​

Alerts and Investigation​

Permission NameDescriptionScope Reference
Alert AccessOpen a Transaction Monitoring alert to view its details, associated transactions and investigation information.AlertAccess
Alert CreateCreate manual transactional or non-transactional alerts from the UI. Displays the Create Alert control on the Entity Alerts and Entity Transactions tabs.AlertCreate
Alert Dashboard AccessAccess and view the Transaction Monitoring Alert Dashboard.AlertDashboardAccess
Alert Dashboard Configuration EditConfigure the columns displayed on the Alert Dashboard.AlertDashboardConfigurationEdit
Entity Profile Transaction ViewView transaction details recorded for an entity from the Entity Profile.EntityProfileTransactionView
TM Risk Configuration AccessAccess and view Transaction Monitoring risk configuration, including configuration used for Behavioural Risk.TMRiskConfigurationAccess
TM Risk Configuration EditCreate and update Transaction Monitoring risk configuration, including Behavioural Risk settings and scoping conditions.TMRiskConfigurationEdit
TM Risk Configuration ApproveApprove Transaction Monitoring risk configuration. Typically restricted to configuration administrators and not normally granted to operational users in Production.TMRiskConfigurationApprove
TM Risk Configuration DeleteDelete Transaction Monitoring risk configuration. Typically restricted to configuration administrators and not normally granted to operational users in Production.TMRiskConfigurationDelete
Transactions Api AccessAccess and use the Transaction Monitoring Transactions API.TransactionsApiAccess
Insights AccessAccess to the Insights feature which provides Transaction Monitoring performance and analytical views.InsightsAccess
Whitelist AccessAccess and view Entity Whitelist entries.EntityWhitelistingAccess
Whitelist EditCreate new Entity Whitelist requests and update existing whitelist entries.EntityWhitelistingEdit
Whitelist ApproveApprove Entity Whitelist requests added for an entity.EntityWhitelistingApprove
Whitelist DeleteRemove an Entity Whitelist entry.EntityWhitelistingDelete

Access​

Permission NameDescriptionScope Reference
Observability AccessAccess the Transaction Monitoring Observability dashboard.ObservabilityViewAccess

Detection Rules​

Permission NameDescriptionScope Reference
Rule View ListView the list of Transaction Monitoring detection rules.RuleViewListAccess
Rule View DetailsView the details of a Transaction Monitoring detection rule.RuleViewDetailsAccess
Rule Draft EditEdit a draft Transaction Monitoring detection rule.RuleDraftEditAccess
Rule PublishPublish a Transaction Monitoring detection rule.RulePublishAccess
Rule ArchiveArchive a Transaction Monitoring detection rule.RuleArchiveAccess
Rule Draft Import/ExportImport and export draft Transaction Monitoring detection rules.RuleDraftImportExportAccess
Rule Audit ActivityView the audit activity trail for Rules.DetectionRuleAuditActivityAccess
Rule Audit ExportRequest, list and download Rule Audit Export reports.DetectionRuleAuditExportAccess
Rule Backtest ViewView backtest results for a Transaction Monitoring detection rule.RuleBacktestViewAccess
Rule Backtest RunRun a backtest on a Transaction Monitoring detection rule.RuleBacktestRunAccess
Rule Group ViewView Transaction Monitoring Rule Groups.RuleGroupViewAccess
Rule Group CreateCreate Transaction Monitoring Rule Groups.RuleGroupCreateAccess
Rule Group EditEdit Transaction Monitoring Rule Groups.RuleGroupEditAccess
Rule Group DeleteDelete Transaction Monitoring Rule Groups.RuleGroupDeleteAccess
Rule Group Activity ViewView activity for Transaction Monitoring Rule Groups.RuleGroupActivityViewAccess

Rules Hub​

Permission NameDescriptionScope Reference
Rules Hub AccessAccess rules hub, and see rule details.RulesHubAccess
Rules Hub EditAdd new or edit existing rules.RulesHubEdit
Rules Hub ApprovalApprove configuration version for publication within the Rules Hub.RulesHubApprove
Rules Hub DeleteDelete rules within the Rules Hub.RulesHubDelete

Deprecated Permissions​

The following permissions are retained for backward compatibility but have been superseded. Avoid assigning them to new Teams.

Document Management​

Permission NameDescriptionScope Reference
Document Management Archive (Legacy)Combines archive and unarchive into a single permission. Retained for backward compatibility and scheduled for removal. Use the separate Document Management - Archive and Document Management - Unarchive permissions instead.DocumentManagementArchive

Loan Origination​

Financial Analysis​

Permission NameDescriptionScope Reference
Financial Analysis ApproveUsed to approve settings for Financial Analysis.FinancialAnalysisApprove

Transaction Monitoring​

Access​

Permission NameDescriptionScope Reference
Compliance Officer Role AccessSuperseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Compliance Officer.TransactionMonitoringComplianceOfficerAccess
Customer Success Role AccessSuperseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Customer Success.TransactionMonitoringCustomerSuccessAccess
Manager Role AccessSuperseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Manager.TransactionMonitoringManagerAccess
MLRO Role AccessSuperseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a MLRO.TransactionMonitoringMLROAccess
Product Admin Role AccessSuperseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Product Admin.TransactionMonitoringProductAdminAccess
Screening Analyst Role AccessSuperseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Screening Analyst.TransactionMonitoringScreeningAnalystAccess
Senior Compliance Officer Role AccessSuperseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Senior Compliance Officer.TransactionMonitoringSeniorComplianceOfficerAccess
Super User Role AccessSuperseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a Super User.TransactionMonitoringSuperUserAccess
TMAnalyst Role AccessSuperseded by the granular Transaction Monitoring permissions and hidden in regions where legacy role permissions are disabled. Access Transaction Monitoring functionalities as a TM Analyst.TransactionMonitoringTMAnalystAccess
Alert Configuration AccessControls access to the Alert Metadata Configuration section within the Reference Data domain.AlertConfigurationAccess
Alert Configuration ApproveControls approval to the Alert Metadata Configuration section within the Reference Data domain.AlertConfigurationApprove
Alert Configuration EditControls the ability to edit the Alert Metadata Configuration section within the Reference Data domain.AlertConfigurationEdit