Role-Based Access Control
Define roles with granular permissions per module, action, and data type — from Super Admin to Read-Only, or any custom role your organisation needs.
Role-Based Access Control (RBAC) is the permission layer that governs what every user can see and do on the platform. Rather than managing permissions per individual user, you define roles — each with a precise set of permissions per module, action type, and data category — and assign users to roles. Every permission check is enforced at the application layer, ensuring that no user can access a function or data record beyond their authorised scope.
Everything you need, nothing you don't
Pre-Built System Roles
Out-of-the-box roles for common job functions: Super Admin, Branch Manager, Teller, Loan Officer, Credit Analyst, Auditor, Agent, and Read-Only — ready to assign immediately.
Custom Role Builder
Create any number of custom roles by selecting the exact combination of module access, action permissions (view, create, edit, approve, delete), and data scope rules.
Module-Level Permissions
Control access at the module level — a Teller role can access the Payments and Cash modules but not the Lending or Reporting modules.
Action-Level Granularity
Within each module, control which actions each role can perform — view, create, edit, approve, reverse, export — independently. A Viewer can see loans but not disburse them.
Data Scope Rules
Restrict users to records within their own branch, region, or assigned customer portfolio — so a branch teller only sees their branch's transactions, not the whole network.
Role Assignment per Branch
A user can hold different roles at different branches — Head Office Analyst at HQ, but Read-Only at a field branch — with permissions switching automatically based on login context.
Role Change Audit
Every role assignment and permission change is logged in the audit trail — who made the change, when, and from which IP address.
Temporary Elevated Access
Grant time-limited elevated permissions to a user for a specific task — with automatic expiry and a notification to the security admin when the temporary access is granted and when it expires.
Built for your team
Define and maintain the permission structure that governs your entire platform — ensuring every user has exactly the access they need and nothing more.
Verify that sensitive functions — write-offs, bulk disbursements, configuration changes — are restricted to authorised personnel, with an immutable log of every permission assignment.
Request the correct role for new team members, knowing that the role definition ensures they can do their job without inadvertently accessing information outside their remit.
Ready to activate Role-Based Access Control?
Sign up free and configure Role-Based Access Control in minutes — or book a demo and we'll walk you through it live.