Skip to main content
Business permissions apply per entity. A role on one entity does not grant access to another.

Role matrix

The entity roles are Owner, Admin, Finance, Member and Accountant. The shared authorization checks grant these permissions: These are entity permission gates. Individual actions can also require identity verification, account ownership or vault access. The Accountant role passes the member gate, including payroll upload and validation; it does not pass the finance or admin gate. Private vault balances and history have separate visibility checks. Card management checks ownership of the card’s account. The matrix does not grant card issuance or freeze access across an entity.

Vault approvals

An entity role does not make you an on-chain signer. Transfer approval depends on vault membership, signing authority and the vault’s required signatures. An eligible Member can be a vault signer without gaining finance access to initiate transfers. Review the amount, destination, network and proposal before approving with the method shown for your account. Follow the proposal’s status through execution. A collected signature is not proof that the transfer has settled.

Invite a teammate

An Owner or Admin can invite a teammate to an entity. Choose the access offered in the invitation flow and have the teammate accept the invitation. The invitation flow labels vault access as Admin, Signer or Viewer. These map to entity roles Admin, Member and Accountant respectively. They are not additional entity roles. A signer invitation may also need an on-chain membership proposal before the teammate can sign.

Remove a teammate

The entity’s owning user can remove a teammate. This operation removes entity membership and attempts to create the required on-chain removal proposals. Review any reported blockers and complete those proposals; app access removal does not by itself remove every on-chain permission. Review the teammate’s cards separately. Removal does not automatically freeze them. Keep the activity records you need for your own review.

Short-term access

Choose the access needed for the engagement and review it when the work ends. Remove access manually when it is no longer needed.

Programmatic access

For scoped agent access, see the MCP tool reference. The Partner API exposes consented personal user data and partner payouts; it does not expose a user’s business-entity data.

Next