> For the complete documentation index, see [llms.txt](https://docs.finpay.id/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.finpay.id/security/user-and-roles.md).

# User & Roles

Manage dashboard access with role-based permissions. Assign each user the minimum access they need to do their job.

This page explains how to add users, choose the right role, and apply basic access control practices for your team.

{% hint style="info" %}
Only **Administrator Merchant** can manage team members and access.
{% endhint %}

### Before you add a user

Use these principles for a safer setup:

* Grant the lowest access level that still lets the user do their work.
* Separate request and approval duties for disbursements.
* Review user access regularly and remove unused accounts.

{% hint style="warning" %}
For disbursement workflows, assign **Disbursement requestors** and **Disbursement approval** to different users.
{% endhint %}

### Add a new user

{% stepper %}
{% step %}

### Open user management

Sign in to the Finpay Dashboard.

Go to **User → Merchant User**.
{% endstep %}

{% step %}

### Create the account

Click **+ Add**.

Enter the required user details.
{% endstep %}

{% step %}

### Assign a role

Choose the role that matches the user's responsibility:

* Administrator Merchant
* Operation Merchant
* IT Merchant
* Disbursement requestors
* Disbursement approval
* Finance Merchant
* Finance Operation
  {% endstep %}

{% step %}

### Save and verify access

Save the new user.

Ask the user to sign in and confirm the expected menu access.
{% endstep %}
{% endstepper %}

### Update an existing user's role

To change a user's responsibilities:

1. Go to **User → Merchant User**.
2. Select the user account you want to update.
3. Change the assigned role.
4. Save the change.
5. Confirm the updated access is correct.

{% hint style="warning" %}
Apply role changes immediately when a user changes function, team, or approval scope.
{% endhint %}

### Role guide

| Role                        | Best for                                            | Key access                                                                                                                                                                       | Notes                                                    |
| --------------------------- | --------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------- |
| **Administrator Merchant**  | Business owners or senior administrators            | Manage users and access. View reports, balances, settlements, and top-ups. Manage settings, API credentials, IP whitelist, and disbursement setup.                               | Broadest dashboard access.                               |
| **Operation Merchant**      | Operations or support teams                         | View transaction, payment, disbursement, and invoice reports. Export report data. Resend payment notifications.                                                                  | Cannot manage settings or move funds.                    |
| **IT Merchant**             | Developers and technical integration teams          | Manage API credentials. Manage the IP whitelist. Resend notifications.                                                                                                           | No finance or reporting access.                          |
| **Disbursement requestors** | Staff who prepare payout requests                   | Create and manage disbursement requests. View beneficiaries and balance. View and export disbursement reports and details.                                                       | Maker role. Cannot approve its own requests.             |
| **Disbursement approval**   | Supervisors who approve outgoing payments           | Review and approve disbursement requests. Manage beneficiaries. View balances, payment reports, and disbursement reports.                                                        | Checker role. Does not create disbursement requests.     |
| **Finance Merchant**        | Finance and reconciliation teams                    | View transaction, payment, invoice, and disbursement reports. View settlement summaries and balance. Create void transaction requests. View disbursement requests and approvals. | Focused on financial monitoring.                         |
| **Finance Operation**       | Senior finance users with broader operational needs | Manage invoices and payment links. Request disbursements. View reports, settlements, balances, and top-ups. Manage recipients and beneficiaries.                                 | Grant only when broad cross-functional access is needed. |

### Permission summary

<table><thead><tr><th width="223.5555419921875">Permission</th><th>Administrator Merchant</th><th>Operation Merchant</th><th>IT Merchant</th><th>Disbursement requestors</th><th>Disbursement approval</th><th>Finance Merchant</th><th>Finance Operation</th></tr></thead><tbody><tr><td>Create and manage invoices or payment links</td><td>✔</td><td>✔</td><td>✖</td><td>✖</td><td>✖</td><td>✔</td><td>✔</td></tr><tr><td>Manage recipients</td><td>✔</td><td>✖</td><td>✖</td><td>✖</td><td>✖</td><td>✖</td><td>✔</td></tr><tr><td>View, export, and schedule transaction reports</td><td>✔</td><td>✔</td><td>✖</td><td>✔</td><td>✔</td><td>✔</td><td>✔</td></tr><tr><td>View payment reports</td><td>✔</td><td>✔</td><td>✖</td><td>✖</td><td>✔</td><td>✔</td><td>✔</td></tr><tr><td>Process refunds and voids</td><td>✔</td><td>✖</td><td>✖</td><td>✖</td><td>✖</td><td>✔</td><td>✔</td></tr><tr><td>Resend payment notifications</td><td>✔</td><td>✔</td><td>✔</td><td>✖</td><td>✖</td><td>✖</td><td>✔</td></tr><tr><td>Request disbursements</td><td>✖</td><td>✖</td><td>✖</td><td>✔</td><td>✖</td><td>✔</td><td>✔</td></tr><tr><td>Approve disbursements</td><td>✖</td><td>✖</td><td>✖</td><td>✖</td><td>✔</td><td>✔</td><td>✖</td></tr><tr><td>Manage beneficiaries</td><td>✔</td><td>✖</td><td>✖</td><td>✔</td><td>✔</td><td>✖</td><td>✔</td></tr><tr><td>View disbursement reports and details</td><td>✔</td><td>✔</td><td>✖</td><td>✔</td><td>✔</td><td>✔</td><td>✔</td></tr><tr><td>View balance, top-up, and settlement</td><td>✔</td><td>✖</td><td>✖</td><td>✔</td><td>✔</td><td>✔</td><td>✔</td></tr><tr><td>Configure payment and business settings</td><td>✔</td><td>✖</td><td>✖</td><td>✖</td><td>✖</td><td>✖</td><td>✖</td></tr><tr><td>Manage team members and access</td><td>✔</td><td>✖</td><td>✖</td><td>✖</td><td>✖</td><td>✖</td><td>✖</td></tr><tr><td>Manage API credentials and IP whitelist</td><td>✔</td><td>✖</td><td>✔</td><td>✔</td><td>✖</td><td>✖</td><td>✖</td></tr><tr><td>Complete KYC and manage profile</td><td>✔</td><td>✔</td><td>✔</td><td>✔</td><td>✔</td><td>✔</td><td>✔</td></tr></tbody></table>

### Access management best practices

* Limit **Administrator Merchant** accounts to trusted personnel.
* Use separate maker and checker roles for disbursement control.
* Review access after organizational or process changes.
* Remove access immediately for inactive or departed users.

If you also manage network restrictions, see [IP Whitelist](/security/ip-whitelist.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.finpay.id/security/user-and-roles.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
