Skip to main content

Transaction Monitoring Permissions Catalogue

Permissions can be found in the Security configuration > Permissions > Transaction Monitoring domain

Permissions

Permission NameDescriptionNotes
Customer Service AccessAbility to view all pages and features of TM and manage users.The main function is to manage the users and monitor the features to confirm that they work as intended.
Product Admin AccessAbility to view all pages and features of TM.
Super User AccessAbility to view and execute all actions within the platform.This permission allows users to assess alerts in all stages, as well access to Insights and Escalate
TM Analyst AccessAbility to assess alerts in 1st or 2nd review stage.This permission allows users to submit an assessment (ML, TF, Both, FP) for an AML alert that is in 1st or 2nd review stage.
Compliance Officer AccessAbility to assess an alert in Compliance review stage.This permission allows users to submit an assessment for an alert that is Compliance review stage.
Senior Compliance Officer AccessAbility to assess an alert in Compliance review stage, view Business Rules and Team performance and escalated transactions.This permission allows users to submit an assessment for an alert that is in the Compliance review stage. Allows access to Investigate, Insights and Escalate pages.
MLRO AccessMoney Laundering Reporting Officer has the ability to view and manage true positive transactions that might need to be reported to the relevant Financial Intelligence Unit (FIU).Allows view access to Investigate, Insights and Escalate pages.
Manager AccessAbility to view all open alerts and to assign and distribute alerts to Analysts and Compliance users.Managers have access to the Investigate, Entities, and Insights pages.

For further information about User Access and User Management in Fenergo SaaS refer to Configuring Access Management and User Administration.

Detection Rules Permissions

Detection rule permissions control access to the Business Rule Manager. They are configured in CLM Security Configuration and are assigned to teams based on the actions each team should be able to perform.

Detection rule permissions

Permission NameDescriptionNotes
Rule View ListAbility to view the detection rules list.Baseline permission for any user who needs visibility of detection rules.
Rule View DetailsAbility to open and view the details of a detection rule.
Rule Draft EditAbility to create draft detection rules, edit draft detection rules, save changes, copy rules to a new draft, and create new versions.Also allows a draft rule to be submitted for approval.
Rule Backtest RunAbility to run a backtest on a draft detection rule.Only rules in draft state can be backtested.
Rule Backtest ViewAbility to view backtest results for a detection rule.
Rule PublishAbility to approve and publish a draft detection rule.Supports a maker-checker separation when held by a different team to Rule Draft Edit.
Rule ArchiveAbility to archive a published detection rule.
Rule Draft Import/ExportAbility to import and export detection rule definitions.Applies to exporting live rules from one tenant and importing them into another as drafts.

Users only see the actions that are available based on their assigned permissions. For further detail on how these permissions apply across the rule lifecycle refer to The Business Rule Manager.

Rule Group Permissions

Rule Group permissions control access to Rule Groups and alert aggregation. They are listed under Transaction Monitoring in the role management screen.

Permission NameDescriptionNotes
Rule Group ViewAbility to see the Rule Groups page, the group list, and any group's detail view in read-only mode.Required for any other Rule Group permission to be useful.
Rule Group CreateAbility to open the Create new rule group modal and create a new group.
Rule Group EditAbility to open an existing group and change its name, description, member rules, or Alert Aggregation toggle.Changes take effect from the next evaluation window.
Rule Group DeleteAbility to soft-delete a group from the kebab menu on the row or from within the group detail view.Member rules of a deleted group return to ungrouped and continue to run on their own configuration.
Rule Group Activity ViewAbility to see the Activity tab and the audit trail of changes made to any Rule Group.Covers create, edit, soft-delete and aggregation-toggle events.
info

A user with none of these permissions does not see the Rule Groups page anywhere in the application.

For further detail refer to Rule Groups and Alert Aggregation.

Rules Hub Permissions (Entity Data Rules)

Rules Hub permissions control access to Entity Data Rules, which perform initial evaluations of entity and KYC data for use within detection rules. The Rules Hub is accessed from the Transaction Monitoring area.

Permission NameDescriptionNotes
Rules Hub AccessAbility to access the Rules Hub page and view rule details.Baseline permission for the Rules Hub.
Rules Hub EditAbility to view the Rules Hub and add new rules or edit existing rules.Updates to rules are saved as a new version and require approval.
Rules Hub DeleteAbility to select a rule and delete it.
Rules Hub ApprovalAbility to approve a configuration version for publication within the Rules Hub.Only users with this permission can approve a new draft for publication.

For further detail refer to Entity Data Rules (KYC Data).

Considerations

To set up a complete working group to run Transaction Monitoring that is able to investigate and close any alert, there is a minimum number of users and teams needed to be configured.

This can depend on the workflow configuration of the client.

  1. Two eyes policy – 2 different users.
    • Option 1
      • User that belongs to a team with TM Analyst Access
      • User that belongs to a team with Compliance Officer or Senior Compliance Officer Access.
    • Option 2
      • Two users with Super User Access
    • Option 3
      • A combination of Option (1) and (2)
  2. Four eyes policy – 3 different users.
    • Option 1
      • Two different users that belong to a team with TM Analyst Access. So that each of them can execute 1st and 2nd review on the same alert. Please note that one Analyst can only review the alert in one stage.
      • One user with Compliance Officer or Senior Compliance Officer Access
    • Option 2
      • Three users with Super User Access
    • Option 3
      • A combination of Option (1) and (2)

Limitations on TM Permissions setup

TM module does not support users having multiple permissions at the moment.

Therefore, it is important that teams and users are configured respecting the following:

  • A team should be created with only one TM permission.
  • A user should only be assigned one team that has TM permissions.
warning

If such constraints are not respected during the tenant setup, the described functionality and user experience will be compromised and will not work as expected.