Transaction Monitoring Permissions Catalogue
Permissions can be found in the Security configuration > Permissions > Transaction Monitoring domain

| Permission Name | Description | Notes |
|---|---|---|
| Customer Service Access | Ability to view all pages and features of TM and manage users. | The main function is to manage the users and monitor the features to confirm that they work as intended. |
| Product Admin Access | Ability to view all pages and features of TM. | |
| Super User Access | Ability to view and execute all actions within the platform. | This permission allows users to assess alerts in all stages, as well access to Insights and Escalate |
| TM Analyst Access | Ability to assess alerts in 1st or 2nd review stage. | This permission allows users to submit an assessment (ML, TF, Both, FP) for an AML alert that is in 1st or 2nd review stage. |
| Compliance Officer Access | Ability to assess an alert in Compliance review stage. | This permission allows users to submit an assessment for an alert that is Compliance review stage. |
| Senior Compliance Officer Access | Ability to assess an alert in Compliance review stage, view Business Rules and Team performance and escalated transactions. | This permission allows users to submit an assessment for an alert that is in the Compliance review stage. Allows access to Investigate, Insights and Escalate pages. |
| MLRO Access | Money Laundering Reporting Officer has the ability to view and manage true positive transactions that might need to be reported to the relevant Financial Intelligence Unit (FIU). | Allows view access to Investigate, Insights and Escalate pages. |
| Manager Access | Ability to view all open alerts and to assign and distribute alerts to Analysts and Compliance users. | Managers have access to the Investigate, Entities, and Insights pages. |
For further information about User Access and User Management in Fenergo SaaS refer to Configuring Access Management and User Administration.
Detection Rules Permissions
Detection rule permissions control access to the Business Rule Manager. They are configured in CLM Security Configuration and are assigned to teams based on the actions each team should be able to perform.

| Permission Name | Description | Notes |
|---|---|---|
| Rule View List | Ability to view the detection rules list. | Baseline permission for any user who needs visibility of detection rules. |
| Rule View Details | Ability to open and view the details of a detection rule. | |
| Rule Draft Edit | Ability to create draft detection rules, edit draft detection rules, save changes, copy rules to a new draft, and create new versions. | Also allows a draft rule to be submitted for approval. |
| Rule Backtest Run | Ability to run a backtest on a draft detection rule. | Only rules in draft state can be backtested. |
| Rule Backtest View | Ability to view backtest results for a detection rule. | |
| Rule Publish | Ability to approve and publish a draft detection rule. | Supports a maker-checker separation when held by a different team to Rule Draft Edit. |
| Rule Archive | Ability to archive a published detection rule. | |
| Rule Draft Import/Export | Ability to import and export detection rule definitions. | Applies to exporting live rules from one tenant and importing them into another as drafts. |
Users only see the actions that are available based on their assigned permissions. For further detail on how these permissions apply across the rule lifecycle refer to The Business Rule Manager.
Rule Group Permissions
Rule Group permissions control access to Rule Groups and alert aggregation. They are listed under Transaction Monitoring in the role management screen.
| Permission Name | Description | Notes |
|---|---|---|
| Rule Group View | Ability to see the Rule Groups page, the group list, and any group's detail view in read-only mode. | Required for any other Rule Group permission to be useful. |
| Rule Group Create | Ability to open the Create new rule group modal and create a new group. | |
| Rule Group Edit | Ability to open an existing group and change its name, description, member rules, or Alert Aggregation toggle. | Changes take effect from the next evaluation window. |
| Rule Group Delete | Ability to soft-delete a group from the kebab menu on the row or from within the group detail view. | Member rules of a deleted group return to ungrouped and continue to run on their own configuration. |
| Rule Group Activity View | Ability to see the Activity tab and the audit trail of changes made to any Rule Group. | Covers create, edit, soft-delete and aggregation-toggle events. |
A user with none of these permissions does not see the Rule Groups page anywhere in the application.
For further detail refer to Rule Groups and Alert Aggregation.
Rules Hub Permissions (Entity Data Rules)
Rules Hub permissions control access to Entity Data Rules, which perform initial evaluations of entity and KYC data for use within detection rules. The Rules Hub is accessed from the Transaction Monitoring area.
| Permission Name | Description | Notes |
|---|---|---|
| Rules Hub Access | Ability to access the Rules Hub page and view rule details. | Baseline permission for the Rules Hub. |
| Rules Hub Edit | Ability to view the Rules Hub and add new rules or edit existing rules. | Updates to rules are saved as a new version and require approval. |
| Rules Hub Delete | Ability to select a rule and delete it. | |
| Rules Hub Approval | Ability to approve a configuration version for publication within the Rules Hub. | Only users with this permission can approve a new draft for publication. |
For further detail refer to Entity Data Rules (KYC Data).
Considerations
To set up a complete working group to run Transaction Monitoring that is able to investigate and close any alert, there is a minimum number of users and teams needed to be configured.
This can depend on the workflow configuration of the client.
- Two eyes policy – 2 different users.
- Option 1
- User that belongs to a team with TM Analyst Access
- User that belongs to a team with Compliance Officer or Senior Compliance Officer Access.
- Option 2
- Two users with Super User Access
- Option 3
- A combination of Option (1) and (2)
- Option 1
- Four eyes policy – 3 different users.
- Option 1
- Two different users that belong to a team with TM Analyst Access. So that each of them can execute 1st and 2nd review on the same alert. Please note that one Analyst can only review the alert in one stage.
- One user with Compliance Officer or Senior Compliance Officer Access
- Option 2
- Three users with Super User Access
- Option 3
- A combination of Option (1) and (2)
- Option 1
Limitations on TM Permissions setup
TM module does not support users having multiple permissions at the moment.
Therefore, it is important that teams and users are configured respecting the following:
- A team should be created with only one TM permission.
- A user should only be assigned one team that has TM permissions.
If such constraints are not respected during the tenant setup, the described functionality and user experience will be compromised and will not work as expected.