For the complete documentation index, see llms.txt. This page is also available as Markdown.

User & Roles

Manage dashboard access with role-based permissions. Assign each user the minimum access they need to do their job.

This page explains how to add users, choose the right role, and apply basic access control practices for your team.

Only Administrator Merchant can manage team members and access.

Before you add a user

Use these principles for a safer setup:

  • Grant the lowest access level that still lets the user do their work.

  • Separate request and approval duties for disbursements.

  • Review user access regularly and remove unused accounts.

Add a new user

1

Open user management

Sign in to the Finpay Dashboard.

Go to User → Merchant User.

2

Create the account

Click + Add.

Enter the required user details.

3

Assign a role

Choose the role that matches the user's responsibility:

  • Administrator Merchant

  • Operation Merchant

  • IT Merchant

  • Disbursement requestors

  • Disbursement approval

  • Finance Merchant

  • Finance Operation

4

Save and verify access

Save the new user.

Ask the user to sign in and confirm the expected menu access.

Update an existing user's role

To change a user's responsibilities:

  1. Go to User → Merchant User.

  2. Select the user account you want to update.

  3. Change the assigned role.

  4. Save the change.

  5. Confirm the updated access is correct.

Role guide

Role
Best for
Key access
Notes

Administrator Merchant

Business owners or senior administrators

Manage users and access. View reports, balances, settlements, and top-ups. Manage settings, API credentials, IP whitelist, and disbursement setup.

Broadest dashboard access.

Operation Merchant

Operations or support teams

View transaction, payment, disbursement, and invoice reports. Export report data. Resend payment notifications.

Cannot manage settings or move funds.

IT Merchant

Developers and technical integration teams

Manage API credentials. Manage the IP whitelist. Resend notifications.

No finance or reporting access.

Disbursement requestors

Staff who prepare payout requests

Create and manage disbursement requests. View beneficiaries and balance. View and export disbursement reports and details.

Maker role. Cannot approve its own requests.

Disbursement approval

Supervisors who approve outgoing payments

Review and approve disbursement requests. Manage beneficiaries. View balances, payment reports, and disbursement reports.

Checker role. Does not create disbursement requests.

Finance Merchant

Finance and reconciliation teams

View transaction, payment, invoice, and disbursement reports. View settlement summaries and balance. Create void transaction requests. View disbursement requests and approvals.

Focused on financial monitoring.

Finance Operation

Senior finance users with broader operational needs

Manage invoices and payment links. Request disbursements. View reports, settlements, balances, and top-ups. Manage recipients and beneficiaries.

Grant only when broad cross-functional access is needed.

Permission summary

Permission
Administrator Merchant
Operation Merchant
IT Merchant
Disbursement requestors
Disbursement approval
Finance Merchant
Finance Operation

Create and manage invoices or payment links

Manage recipients

View, export, and schedule transaction reports

View payment reports

Process refunds and voids

Resend payment notifications

Request disbursements

Approve disbursements

Manage beneficiaries

View disbursement reports and details

View balance, top-up, and settlement

Configure payment and business settings

Manage team members and access

Manage API credentials and IP whitelist

Complete KYC and manage profile

Access management best practices

  • Limit Administrator Merchant accounts to trusted personnel.

  • Use separate maker and checker roles for disbursement control.

  • Review access after organizational or process changes.

  • Remove access immediately for inactive or departed users.

If you also manage network restrictions, see IP Whitelist.

Last updated