> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kirafin.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

> What each person with dashboard access can do, and who decides it.

Everyone with dashboard access holds one role. The role decides what that person can **do** — move money, reveal credentials, register a webhook endpoint. It does not decide what they can **see**: every role reads everything.

Roles are set by an administrator on your own team, in [Your team](/dashboard/team). You do not ask Kira to change one.

## The five roles

| Role              | What it is for                                                                                       |
| ----------------- | ---------------------------------------------------------------------------------------------------- |
| **Administrator** | Everything, including reading the production credentials off the dashboard and assigning these roles |
| **Operations**    | Moves money, opens accounts, and manages counterparties, sub-clients and requests for information    |
| **Developer**     | Sandbox credentials and webhook endpoints. No money, and no reading the production credentials       |
| **Compliance**    | Onboarding work: counterparties, sub-clients, and answering requests for information                 |
| **Viewer**        | Reads everything, changes nothing                                                                    |

## What every role can do

Reading is not restricted. Accounts, balances, transactions, payouts, counterparties, sub-clients, requests for information and webhook history are visible to everyone, whatever their role.

So is pricing. Asking what a payout or a conversion would cost moves no money and creates nothing, so a Viewer can quote a movement they cannot then make.

Everyone can also see who has access to the account and which role each person holds.

## Who can do what

|                                                                               | Administrator | Operations | Developer | Compliance | Viewer |
| ----------------------------------------------------------------------------- | :-----------: | :--------: | :-------: | :--------: | :----: |
| Read everything                                                               |       ✓       |      ✓     |     ✓     |      ✓     |    ✓   |
| Price a movement                                                              |       ✓       |      ✓     |     ✓     |      ✓     |    ✓   |
| Create and edit a sub-client                                                  |       ✓       |      ✓     |     —     |      ✓     |    —   |
| Save and edit a counterparty                                                  |       ✓       |      ✓     |     —     |      ✓     |    —   |
| Answer a request for information, upload a document, send a verification link |       ✓       |      ✓     |     —     |      ✓     |    —   |
| Open a virtual account                                                        |       ✓       |      ✓     |     —     |      —     |    —   |
| Make a payout or set a liquidation address                                    |       ✓       |      ✓     |     —     |      —     |    —   |
| Reveal the **sandbox** API key and client password                            |       ✓       |      —     |     ✓     |      —     |    —   |
| Manage webhook endpoints, replays and test events                             |       ✓       |      —     |     ✓     |      —     |    —   |
| Read the **production** API key and client password                           |       ✓       |      —     |     —     |      —     |    —   |
| Change what a colleague can do                                                |       ✓       |      —     |     —     |      —     |    —   |
| Invite a teammate                                                             |       ✓       |      —     |     —     |      —     |    —   |

Anything not on this list is open to everyone.

Two rows are worth reading twice.

**Kira issues the production credentials — no role creates them.** You ask Kira for them when you go live, the same way you ask for the sandbox pair. What the role decides is who can then open them on screen: the administrator is the only person who can see and read them off the dashboard. That is the cut the roles are built around, because an API key carries the full power of the account, so whoever can read it can do everything, in the dashboard or outside it.

**Operations and Developer do not overlap.** Whoever moves money does not manage webhook endpoints, and whoever manages webhook endpoints does not move money. Someone who needs both needs Administrator.

## Roles do not scope API keys

A role governs a person in the dashboard. It does not govern an API key: the key carries the full power of the account, whoever holds it and whatever role that person has.

That is why reading the production credentials off the dashboard sits with the administrator alone, and why handing a colleague an API key is not a way to give them dashboard access — see [Access](/dashboard/access).

## Invite teammates

An administrator invites a teammate from **Settings › Team** with **Invite teammate**: their name, work email and role. Kira emails them a link to set their password.

## A change takes effect at once

A new role applies from that person's next action. Nobody signs in again, and there is nothing to wait out.

<Card title="Your team" icon="arrow-right" href="/dashboard/team">
  Change what a colleague can do.
</Card>
