The five roles
What every role can do
Reading is not restricted. Accounts, balances, transactions, payouts, counterparties, sub-clients, requests for information and webhook history are visible to everyone, whatever their role. So is pricing. Asking what a payout or a conversion would cost moves no money and creates nothing, so a Viewer can quote a movement they cannot then make. Everyone can also see who has access to the account and which role each person holds.Who can do what
Anything not on this list is open to everyone.
Two rows are worth reading twice.
Kira issues the production credentials — no role creates them. You ask Kira for them when you go live, the same way you ask for the sandbox pair. What the role decides is who can then open them on screen: the administrator is the only person who can see and read them off the dashboard. That is the cut the roles are built around, because an API key carries the full power of the account, so whoever can read it can do everything, in the dashboard or outside it.
Operations and Developer do not overlap. Whoever moves money does not manage webhook endpoints, and whoever manages webhook endpoints does not move money. Someone who needs both needs Administrator.
Roles do not scope API keys
A role governs a person in the dashboard. It does not govern an API key: the key carries the full power of the account, whoever holds it and whatever role that person has. That is why reading the production credentials off the dashboard sits with the administrator alone, and why handing a colleague an API key is not a way to give them dashboard access — see Access.Invite teammates
An administrator invites a teammate from Settings › Team with Invite teammate: their name, work email and role. Kira emails them a link to set their password.A change takes effect at once
A new role applies from that person’s next action. Nobody signs in again, and there is nothing to wait out.Your team
Change what a colleague can do.