Skip to main content

Permissions Catalogue

Permissions are pre-defined within the Fenergo SaaS application and represent a series of functional capabilities across the various features within the application.

Permissions determine what a user can do within the system. They cover administrative, operational and configuration based user activities.

From an Operational user's POV, permissions control what the user can access, create, cancel, etc. For example, a user may have permission to initiate journey, access client entity data, and trigger screening. Permissions also govern what the Configuration user is allowed to do within the system whether including operations such as create, edit, and approve with respect to configuration sets. For example, a user may have permission to create Policy drafts, edit the requirements within it, and then approve any changes to policies.

Permissions are organized by Domain and are pre-defined per specific API capabilities within the system. Permissions are broken up into the following categories:

  • Access - the ability to access a feature
  • Edit - the ability to edit within a feature
  • Create - the ability to create an instance of an object related to feature
  • Cancel - the ability to cancel an activity within a feature
  • Delete - the ability to delete within a feature
  • Approve - the ability to approve within a feature
  • Archive - the ability to archive within a feature

Permissions are added to Teams. While the individual permissions are pre-configured and cannot be changed, Teams are configurable and the the combinations of permissions contained within team are fully configurable.

This document also includes suggested "User Personas" to help understand logical combinations of permissions across different job functions.

Within this document, the term "Lower-Level Environment" is used to describe non-production environments such as DEV, SIT, UAT, PRE-PROD.

Administration

Configuration Exchange

Permission NameDescriptionNotes
Configuration Exchange AccessAbility to access the Configuration Exchange featureThis permission allows users to go into the Configuration Exchange feature and explore. It's the most basic permission for the feature, however edit permissions are also required to be able to Import configuration to a tenant.
Configuration Exchange EditAbility to use Configuration Exchange to import draft items to/from permitted domainsThis permission is typically limited to an organization's Release Management function in Production and Pre-Prod tenants but is often made available to System Configuration users in lower-level environments such as Dev and UAT.
Configuration Exchange PublishAbility to choose to Publish imported items to permitted domainsThis permission is required to access the 'Import in a Published State' toggle within Configuration Exchange. Domain 'Approval' permissions are also required to successfully publish imported configuration
warning

A Release Management user with the permission Configuration Exchange Edit requires Access and Edit permissions within each of the various domains they are promoting configuration to/from.

Configuration Release Hub

Permission NameDescriptionNotes
Configuration Release Hub AccessAbility to access the Configuration Release Hub feature and view Configuration BundlesAllows users to navigate to Configuration Release Hub → Configuration Bundles and view bundle contents. This permission does not allow users to create, edit, or import bundles.
Configuration Release Hub Create BundleAbility to create and edit Configuration Bundles within the source tenantTypically granted to configuration or release teams responsible for building and maintaining bundles in the Dev tenant. Enables users to create drafts, edit bundle details, and add/remove selected items.
Configuration Release Hub Import BundleAbility to import a published Configuration Bundle version to a target tenant via APIRequired to initiate import endpoints. Users do not require domain-level configuration permissions in the target environment. Suitable for automation users, pipelines, and deployment functions.

Data Migration

Permission NameDescriptionNotes
Data Migration AdministratorAbility to execute Data Migration activitiesThis permission is typically limited to an organization's Release Management function in all client environments.

ETL (Extract Transform Load)

Permission NameDescriptionNotes
ETL AdministratorAbility to access ETL tool, Create and Run migrationsRequired by Migration users in lower-level environments to access the ETL configuration. Generally, only provided to Application Support Teams in a Production environment.
Agency ETL AdministratorAbility to access and use Agency ETL task for bulk uploadRequired to view and use the Agency ETL task in an Agency Request Journey. This permission doesn't affect access to the ETL tool for migrations.

Security

Permission NameDescriptionNotes
Security Configuration AccessAbility to access the Security Configuration featureRequired by System Configuration users in lower-level environments to access the Security Configuration. Generally, only provided to Application Support Teams in a Production environment. It is necessary for a user to have this Permission in order to make use of the other permissions for this Domain via the UI and to Access the User Management screen.
Security Configuration CreateAbility to create new Teams via the Security Configuration featureRequired by System Configuration users in lower-level environments to create Teams. This permission is not typically granted to users in a Production environment.
Security Configuration EditAbility to edit Teams via the Security Configuration feature including assigning Permissions to a team and cloning an existing teamRequired by System Configuration users in lower-level environments to configure Teams. This permission is not typically granted to users in a Production environment.
Security Configuration DeleteAbility to delete Teams via the Security Configuration feature.Required by System Configuration users in lower-level environments to delete Teams. This permission is not typically granted to users in a Production environment.
Security User AdministrationAbility to access the User Administration featureRequired by User Administration User to assign Teams to individual Users. This permission is typically limited to an organization's User Administration function in a Production environment but is often made available to System Configuration users in lower-level environments.
Security Create New UserAbility to create a new user in this tenantRequired by User Administration User to create new Users. This permission is typically limited to an organization's User Administration function in a Production environment but is often made available to System Configuration users in lower-level environments.
Security Edit UsersAbility to access the Edit User detailsRequired by User Administration User to edit Users. This permission is typically limited to an organization's User Administration function in a Production environment but is often made available to System Configuration users in lower-level environments.
Security Remove UsersAbility to remove Users from a tenantRequired by User Administration User to remove Users. This permission is typically limited to an organization's User Administration function in a Production environment but is often made available to System Configuration users in lower-level environments.

Configuration Permissions

Credit Policy

Permission NameDescriptionNotes
Credit Policy Configuration AccessAbility to access the configurations within Credit Policy featureRequired by System Configuration users in lower-level environments to access the Credit Policy Configuration Feature. Generally, only provided to Application Support Teams in a Production environment.
Credit Policy Configuration EditAbility to create new and edit existing configurations within Credit Policy featureRequired by System Configuration users in lower-level environments to create and modify configuration within the Credit Policy Configuration Feature. This permission is not typically granted to users in a Production environment.
Credit Policy Configuration DeleteAbility to delete existing configurations within Credit Policy featureRequired by System Configuration users in lower-level environments to delete a published version or full record. This permission is not typically granted to users in a Production environment.
Credit Policy Configuration ApproveAbility to approve configurations within Credit Policy featureRequired by System Configuration users in lower-level environments to approve a Credit Policy Configuration. This permission is not typically granted to users in a Production environment.
Credit Policy Configuration ArchiveAbility to archive configurations within Credit Policy featureRequired by System Configuration users in lower-level environments to archive a Credit Policy Configuration version. This permission is not typically granted to users in a Production environment.

Data Protection

Permission NameDescriptionNotes
Data Protection Configuration AccessAbility to access and interact and navigate into the Data Protection domain/screenRequired by System Configuration users responsible for reviewing Data Protection Regimes.
Data Protection Configuration CreateAbility to create new Data Protection regimes via the ADD buttonRequired by System Configuration users responsible for creating new Data Protection Regimes.
Data Protection Configuration EditAbility to edit existing Data Protection regimesRequired by System Configuration users responsible for editing existing Data Protection Regimes.
Data Protection Configuration DeleteAbility to delete existing Data Protection regimesRequired by System Configuration users responsible for deleting existing Data Protection Regimes.
Data Protection Configuration ApproveAbility to Approve versions of Entity Check Configuration.Required by System Configuration users in lower-level environments to Approve Data Protection Entity Check configuration. This permission is not typically granted to users in a Production environment.
Data Protection Configuration ArchiveAbility to Archive versions of Entity Check Configuration.Required by System Configuration users in lower-level environments to Archive Data Protection Entity Check configuration. This permission is not typically granted to users in a Production environment.

Digital ID&V Configuration

Permission NameDescriptionNotes
Digital ID&V ConfigurationAbility to access the Digital ID&V ConfigurationUsers with this permission can configure the Fenergo Native Digital ID&V solution or Jumio integration.

Document Configuration

Permission NameDescriptionNotes
Document Configuration AccessAbility to access the Document Types featureRequired by System Configuration users in lower-level environments to access the Document Types Configuration area. Generally, only provided to Application Support Teams in a Production environment. It is necessary for a user to have this Permission to make use of the other permissions for this Domain via the UI.
Document Configuration EditAbility to create new Document Types sets and update existing Document Types setsRequired by System Configuration users in lower-level environments to create new sets of Document Types as well as make changes to existing versions of Document Types in Fenergo SaaS. This permission is not typically granted to operational users in a Production environment.
Document Configuration DeleteAbility to delete existing Document TypesRequired by System Configuration users in lower-level environments to delete Document Types. This permission is not typically granted to operational users in a Production environment.
Document Configuration ApproveAbility to approve a set of Document Types that is submitted for publicationRequired by System Configuration users in lower-level environments to approve or reject a set of Document Types after it has been submitted for approval. This permission is not typically granted to operational users in a Production environment.
Document Configuration ArchiveAbility to archive a set of Document TypesRequired by System Configuration users in lower-level environments to archive a set of Document Types. This permission is not typically granted to operational users in a Production environment.

eSignature Configuration

Permission NameDescriptionNotes
eSignature Configuration AccessAbility to access the eSignature Configuration featureRequired by System Configuration users who will need to see the configuration set up between eSign vendors and Fenergo SaaS.
eSignature Configuration CreateAbility to create new configurations within the eSignature Configuration featureRequired by System Configuration users who will be establishing eSignature capability and connection between eSign vendors and Fenergo SaaS.
eSignature Configuration EditAbility to edit existing configurations within the eSignature Configuration featureRequired by System Configuration users who will be updating eSignature capability and connection between eSign vendors and Fenergo SaaS.
eSignature Configuration DeleteAbility to delete configurations within the eSignature Configuration featureRequired by System Configuration users who will be removing eSignature capability between and eSign vendor and Fenergo SaaS.

Event Ingress

Permission NameDescriptionNotes
Get Event DetailsAbility to retrieve Ingress Event DetailsThis permission allows users to retrieve details on Event Ingress messages such as Event Type, Processing Status and further details. Users with this permission will see Integration Hub in the Dashboard menu.
Get Event PayloadAbility to retrieve Ingress Event PayloadThis permission allows users to retrieve past event payload, and processed message for when event subtype is DataImport. Take special care when assigning this permission in a Production-like environment as the messages can contain sensitive data.

External Data Configuration

Permission NameDescriptionNotes
External Data Mapper AccessAbility to access the External Data Mapper toolThis permission is used by SaaS engineering or clients to access the External Data Mapping APIs [GET] to make changes to the External Data Provider attributes mapping.
External Data Mapper EditAbility to use the External Data Mapper tool to make changes to the mappingThis permission is used by SaaS engineering or clients to make changes to the External Data Mapping APIs [PUT] to make changes to the External Data Provider attributes mapping.
External Data Configurator AccessAbility to access the External Data Configuration page and interact with the associated APIsThis permission is used by SaaS engineering or clients to access the External Data Configuration page for setting up an External Data Provider.
External Data Configurator CreateAbility to create new External Data ConfigurationsThis permission is used by SaaS engineering as a part of Tenant set up and is not required by clients to be applied to users.
External Data Configurator EditAbility to edit within the External Data Configuration pageThis permission is used by SaaS engineering or clients to make edits within the External Data Configuration page and is also required for changes to a specific provider.
External Data Configurator DeleteAbility to delete External Data ConfigurationsThis permission is used by SaaS engineering as a part of Tenant management and is not required by clients to be applied to users.

Impact Assessment

Permission NameDescriptionNotes
Risk Impact Assessment AccessAbility to View a completed Risk Impact AssessmentThis permission allows users to view the outcomes of a completed Risk Impact Assessment. The permission is needed by users who don't have Edit permission but are involved in the process of evaluating changes to risk configuration.
Risk Impact Assessment EditAbility to initiate a Risk Impact AssessmentThis permission allows users to populate the parameters and run a Risk Impact Assessment. The permission is required by users who make changes to stable risk configuration and need to evaluate that impacts match expectations.

Integration Flows Configuration

Permission NameDescriptionNotes
Configuration AccessAbility to view Flow Configurations in Flow StudioRequired by System Configuration users in lower-level environments to access Flow Configurations in Flow Studio. Generally, only provided to Application Support Teams in a Production environment. It is necessary for a user to have this Permission to make use of the other permissions for this Domain via the UI.
Configuration EditAbility to interact with and save changes to a Flow Configuration in Flow StudioRequired by System Configuration users in lower-level environments to make changes to the Flow Configuration in Flow Studio Feature. This permission is not typically granted to users in a Production environment.
Configuration ApproveAbility to approve/reject a Flow Version that is submitted for publicationRequired by System Configuration users in lower-level environments to approve or reject a Flow Version changes. This permission is not typically granted to users in a Production environment.
Configuration DeleteAbility to delete a FlowRequired by System Configuration users in lower-level environments to delete a Flow. This permission is not typically granted to users in a Production environment.
Mapping EditAbility to interact with and save changes to a Schema or Mapping Configuration in Flow StudioRequired by System Configuration users in lower-level environments to make changes to the Schema or Mapping Configuration in Flow Studio Feature. This permission is not typically granted to users in a Production environment.
Auth Configuration AccessAbility to view Custom Authentication configurations in Flow StudioRequired by System Configuration users in lower-level environments to view Custom Authentication configuration in Flow Studio Feature. This permission is not typically granted to users in a Production environment.
Auth Configuration EditAbility to change Custom Authentication configurations in Flow StudioRequired by System Configuration users in lower-level environments to make changes to the Custom Authentication configuration in Flow Studio Feature. This permission is not typically granted to users in a Production environment.

Journey Builder

Permission NameDescriptionNotes
Journey Builder AccessAbility to access the Journey Builder featureRequired by System Configuration users in lower-level environments to access the Journey Builder Feature. Generally, only provided to Application Support Teams in a Production environment. It is necessary for a user to have this Permission to make use of the other permissions for this Domain via the UI.
Journey Builder EditAbility to interact with and save changes to the Journey Builder featureRequired by System Configuration users in lower-level environments to make changes to the Journey Builder Feature. This permission is not typically granted to users in a Production environment.
Journey Builder ApproveAbility to approve a Journey schema that is submitted for publicationRequired by System Configuration users in lower-level environments to approve a journey schema. This permission is not typically granted to users in a Production environment.
Journey Builder ArchiveAbility to archive a Journey version or schemaRequired by System Configuration users in lower-level environments to archive a journey schema. This permission is not typically granted to users in a Production environment.
Journey Builder DeleteAbility to delete a Journey schemaRequired by System Configuration users in lower-level environments to delete a journey version or schema. This permission is not typically granted to users in a Production environment.
Journey Launch Control AccessAbility to Access the Journey Launch Controls configurationRequired by System Configuration users in lower-level environments to access Journey Launch Controls configuration. This permission is not typically granted to users in a Production environment, but may be granted so that bespoke Users in a Production environment can understand the underlying logic of the configured Journey Launch Controls.
Journey Launch Control DeleteAbility to delete existing Journey Launch Controls ConfigurationRequired by System Configuration users in lower-level environments to Delete Journey Launch Rules configuration. This permission is not typically granted to users in a Production environment.
Journey Launch Control EditAbility to create and edit Journey Launch Controls configurationRequired by System Configuration users in lower-level environments to Delete Journey Launch Rules configuration. This permission is not typically granted to users in a Production environment.

Journey Configuration

Permission NameDescriptionNotes
Journey Configuration EditAbility to update tenant-wide journey configuration settingsRequired by System Configuration users in lower-level environments to manage global journey behavior settings such as cancellation comment requirements. This permission is not typically granted to users in a Production environment.

Journey Scheduler

Permission NameDescriptionNotes
Journey Scheduler AccessAbility to access the Journey Scheduler featureRequired by System Configuration users in lower-level environments to access the Journey Scheduler Feature. Generally, only provided to Application Support Teams in a Production environment. It is necessary for a user to have this Permission to make use of the other permissions for this Domain via the UI.
Journey Scheduler EditAbility to create new Journey Schedules and update existing Journey SchedulesRequired by System Configuration users in lower-level environments to create new Journey Schedules as well as make changes to existing Journey Schedules in Fenergo SaaS. This permission is not typically granted to users in a Production environment.
Journey Scheduler DeleteAbility to delete existing Journey SchedulesRequired by System Configuration users in lower-level environments to delete existing Journey Schedules. This permission is not typically granted to users in a Production environment.
Journey Scheduler ApproveAbility to approve a Journey Scheduler that is submitted for publicationRequired by System Configuration users in lower-level environments to approve a Journey Schedule. This permission is not typically granted to users in a Production environment.
Journey Scheduler ArchiveAbility to archive a Journey Schedule versionRequired by System Configuration users in lower-level environments to archive a Journey Schedule. This permission is not typically granted to users in a Production environment.

Localisation

Permission NameDescriptionNotes
Localisation AccessAbility to access the Localisation featureRequired by System Configuration users in lower-level environments to access the Localisation Feature. Typically, this is only provided to Application Support Teams in a Production environment.
Localisation EditAbility to interact with the Localisation feature including creating new Localisation versions and loading dictionariesRequired by System Configuration users in lower-level environments to create and modify Localisation configuraiton. This permission is not typically granted to users in a Production environment.
Localisation ApproveAbility to approve a Localisation version that is submitted for publicationRequired by System Configuration users in lower-level environments to approve a Localisation version. This permission is not typically granted to users in a Production environment.
Localisation ArchiveAbility to archive a Localisation versionRequired by System Configuration users in lower-level environments to archive a Localisation version. This permission is not typically granted to users in a Production environment.
Localisation DeleteAbility to delete a Localisation version or full recordRequired by System Configuration users in lower-level environments to delete a Localisation version or full record. This permission is not typically granted to users in a Production environment.

Logging Centre

Permission NameDescriptionNotes
Logging Centre AccessAbility to access Integration LogsThis permission allows users to access logs produced by integration services in Fenergo SaaS. Currently this is limited to Event Ingress DataImport messages.
Logging Centre EditAbility to configure Integration LogsThis permission allows users to change log settings (e.g. opt-in/out) used by integration services in Fenergo SaaS.

Lookup Configuration

Permission NameDescriptionNotes
Reference Data Editor AccessAbility to access the Reference Data featureRequired by System Configuration users in lower-level environments to access the Reference Data Feature. Typically, this is only provided to Application Support Teams in a Production environment, however in some cases this may be provisioned to business users to stay informed on the reference data being used across Production. Note: A user requires the 'Lookup Access' Permission to interact with the Reference Data feature.
Reference Data Editor EditAbility to interact with the Reference Data feature including creating new reference data lists, creating new drafts, editing drafts, deleting values from a draft and submitting drafts for approvalRequired by System Configuration users in lower-level environments to create and modify Reference Data lists within the Reference Data Feature. This permission is not typically granted to users in a Production environment. Note: A user requires the 'Lookup Access' Permission to interact with the Reference Data feature.
Reference Data Editor ApproveAbility to approve a Reference Data List version that is submitted for publicationRequired by System Configuration users in lower-level environments to approve a Reference Data list version. This permission is not typically granted to users in a Production environment. Note: A user requires the 'Lookup Access' Permission in order to properly interact with the Reference Data feature.
Reference Data Editor ArchiveAbility to archive a Reference Data List versionRequired by System Configuration users in lower-level environments to archive a Reference Data List version. This permission is not typically granted to users in a Production environment. Note: A user requires the 'Lookup Access' Permission to interact with the Reference Data feature.
Reference Data Editor DeleteAbility to delete a Reference Data list version or full recordRequired by System Configuration users in lower-level environments to delete a Reference Data List version or full record. This permission is not typically granted to users in a Production environment. Note: A user requires the 'Lookup Access' Permission to interact with the Reference Data feature.

Naratives Access/Management

Permission NameDescriptionNotes
Naratives AccessAbility to view the Narratives tab on the Entity Profile PageRequired for anyone who should be able to view or provide narratives
Compliance Narratives AccessAbility to view the 'Compliance Narratives' section (and any added narratives via the eye button) within the Narratives tab of the EPPRequired for anyone who should be able to view 'Compliance Narratives'
Compliance Narratives CreateAbility to see the 'Add' button and create new 'Compliance Narratives'Required for any client facing users who will interact with clients on compliance matters
Compliance Narratives EditAbility to see the edit button (pencil) and use it to edit existing 'Compliance Narratives'Required for any client facing or Compliance Manager users who may need to adjust an existing 'Compliance Narrative'
Compliance Narratives DeleteAbility to see the delete button (bin/trash) and use it to delete existing 'Compliance Narratives'Required for any client facing or Compliance Manager users who may need to delete an existing 'Compliance Narrative'
Business Narratives AccessAbility to view the 'Business Narratives' section (and any added narratives via the eye button) within the Narratives tab of the EPPRequired for anyone who should be able to view Business narratives
Business Narratives CreateAbility to see the 'Add' button and create new 'Business Narratives'Required for any client facing users who will interact with clients on Business matters
Business Narratives EditAbility to see the edit button (pencil) and use it to edit existing 'Business Narratives'Required for any client facing or Business Manager users who may need to adjust an existing 'Business Narrative'
Business Narratives DeleteAbility to see the delete button (bin/trash) and use it to delete existing 'Business Narratives'Required for any client facing or Business Manager users who may need to delete an existing 'Business Narrative'

Policy Configuration

Permission NameDescriptionNotes
Policy Configuration AccessAbility to access the Policy Configuration feature including the Policy search featureRequired by System Configuration users in lower-level environments to access the Policy Configuration Feature. Generally, only provided to Application Support Teams in a Production environment.
Policy Configuration EditAbility to interact with the Policy Configuration feature including creating new Policies, editing drafts and submitting policy drafts for approvalRequired by System Configuration users in lower-level environments to create and modify Policies within the Policy Configuration Feature. This permission is not typically granted to users in a Production environment.
Policy Configuration ApproveAbility to approve a Policy version that is submitted for publicationRequired by System Configuration users in lower-level environments to approve a Policy version. This permission is not typically granted to users in a Production environment.
Policy Configuration ArchiveAbility to archive a Policy versionRequired by System Configuration users in lower-level environments to archive a Policy version. This permission is not typically granted to users in a Production environment.
Policy Configuration DeleteAbility to delete a Policy version or full recordRequired by System Configuration users in lower-level environments to delete a Policy version or full record. This permission is not typically granted to users in a Production environment.

Portal

Permission NameDescriptionNotes
Portal Configuration AccessAbility to access the Portal Configuration featureRequired by System Configuration users in lower-level environments to access the Portal Configuration Feature. This permission is not typically granted to users in a Production environment.
Portal Configuration EditAbility to edit the Portal Configuration featureRequired by System Configuration users in lower-level environments to make changes within the Portal Configuration Feature. This permission is not typically granted to users in a Production environment.
Portal User AdministrationAbility to update and create portal users and link relevant legal entities they can have access to through portalRequired by System Configuration users in lower-level environments to make updates to the portal user pool, they can create, edit and inactivate users. The can also edit the Legal Entities linked to each user. This permission is not typically granted to users in a Production environment.
Portal Administration User DeleteAbility to delete portal users from the portal databaseRequired by System Configuration users in lower-level environments to remove portal users. This permission is not typically granted to users in a Production environment

Product Configuration

Permission NameDescriptionNotes
Product Configuration AccessAbility to access the Product ConfigurationRequired by System Configuration users in lower-level environments to access the Product Configuration. Generally, only provided to Application Support Teams in a Production environment.
Product Configuration ApprovalAbility to approve a Product Requirement Set version that is submitted for publicationRequired by System Configuration users in lower-level environments to approve a Requirement Set version. This permission is not typically granted to users in a Production environment.
Product Configuration ArchiveAbility to archive a Requirement Set versionRequired by System Configuration users in lower-level environments to archive a Requirement Set version. This permission is not typically granted to users in a Production environment.
Product Configuration DeleteAbility to delete a Product Requirement Set version or full recordRequired by System Configuration users in lower-level environments to delete a Product Requirement Set version or full record. This permission is not typically granted to users in a Production environment.
Product Configuration EditAbility to interact with the Product Configuration feature including creating new Product Requirement Sets, editing drafts and submitting drafts for approvalRequired by System Configuration users in lower-level environments to create and modify Requirement Sets within Product Configuration. This permission is not typically granted to users in a Production environment.

Review Journey Scheduling Configuration & Access

Permission NameDescriptionNotes
Review Journey Scheduling AccessAbility to access the Review Journey Scheduling featureRequired by System Configuration users in lower-level environments. Generally, only provided to Application Support Teams in a Production environment. It is necessary for a user to have this Permission to make use of the other permissions for this Domain via the UI.
Review Journey Scheduling EditAbility to create and update Scoping rules within Review Journey SchedulingRequired by System Configuration users in lower-level environments. This permission is not typically granted to users in a Production environment.
Review Journey Scheduling DeleteAbility to delete existing Review Journey Scheduling Scoping Rule instances and draftsRequired by System Configuration users in lower-level environments. This permission is not typically granted to users in a Production environment.
Review Journey Scheduling ApproveAbility to submit and approve a Review Journey Scheduling Scoping rule for publicationRequired by System Configuration users in lower-level environments. This permission is not typically granted to users in a Production environment.
Review Journey Scheduling ArchiveAbility to archive a Review Journey Scheduling Scoping rule versionRequired by System Configuration users in lower-level environments. This permission is not typically granted to users in a Production environment.
Scheduled Review Access / Journey AccessAbility to view Scheduled Reviews via Review query API and via the Entity Profile PageRequired by operational users to view Scheduled Reviews. Most users will already have Journey Access and will not require additional permissions to view Scheduled Reviews.
Scheduled Review EditAbility to create or update scheduled reviews via Review command APIsRequired by systems or technical users to manage Scheduled Reviews directly.
Scheduled Review DeleteAbility to delete scheduled reviews via Review command APIsRequired by systems or technical users to manage Scheduled Reviews directly.

Risk Configuration

Permission NameDescriptionNotes
Risk Configuration AccessAbility to access the Risk Configuration featureRequired by System Configuration users in lower-level environments to access the Policy Configuration Feature. Generally, only provided to Application Support Teams in a Production environment.
Risk Configuration EditAbility to interact with the Risk Configuration feature including creating new risk models, editing risk models, submitting risk models for approval and modifying scoping rulesRequired by System Configuration users in lower-level environments to create and modify Risk related content within the Risk Configuration Feature. This permission is not typically granted to users in a Production environment.
Risk Configuration ApproveAbility to approve a Risk model version that is submitted for publicationRequired by System Configuration users in lower-level environments to approve a Risk model version. This permission is not typically granted to users in a Production environment.
Risk Configuration ArchiveAbility to archive a Risk model versionRequired by System Configuration users in lower-level environments to archive a Risk model version. This permission is not typically granted to users in a Production environment.
Risk Configuration DeleteAbility to delete a Risk model version or full recordRequired by System Configuration users in lower-level environments to delete a Risk model version or full record. This permission is not typically granted to users in a Production environment.

Screening Configuration

Permission NameDescriptionNotes
Screening Configuration AccessAbility to access the Screening Configuration featureRequired by System Configuration users in lower-level environments to access the Screening Configuration Feature. Generally, only provided to Application Support Teams in a Production environment.
Screening Configuration EditAbility to interact with the Screening Configuration feature including modifying the credentials of the screening provider and adjusting list settingsRequired by System Configuration users in lower-level environments to modify Screening configuration. This permission is not typically granted to users in a Production environment.
Screening Configuration CreateAbility to create a new configuration for a screening providerRequired by System Configuration users in lower-level environments to create Screening configuration. This permission is not typically granted to users in a Production environment.
Screening Configuration DeleteAbility to delete an existing configuration for a screening providerRequired by System Configuration users in lower-level environments to create Screening configuration. This permission is not typically granted to users in a Production environment.
Screening Configuration ArchiveAbility to archive an existing screening scoping ruleRequired by System Configuration users in lower-level environments to create Screening Scoping Rules configuration. This permission is not typically granted to users in a Production environment.
Screening Configuration ApproveAbility to approve an existing screening scoping ruleRequired by System Configuration users in lower-level environments to create Screening Scoping Rules configuration. This permission is not typically granted to users in a Production environment.
Screening CreateAbility to create a screening batchRequired by System Configuration users who will be creating screening requests.
Screening AccessAbility to access a screening batchRequired by System Configuration users who will be accessing screening results.
Screening EditAbility to edit a screening batchRequired by System Configuration users who will be editing screening results.

Shared Data Template Configuration

Permission NameDescriptionNotes
Shared Data Template AccessAbility to access the Shared Data Template feature.This is a requisite permission that must be assigned in order for the other Shared Data Template permissions to be usable.
Shared Data Template EditAbility to edit existing draft versions of Shared Data Templates.Required by System Configuration users in lower-level environments to edit Shared Data Template draft configuration. This permission is not typically granted to users in a Production environment.
Shared Data Template CreateAbility to create new draft versions Shared Data Templates.Required by System Configuration users in lower-level environments to create Shared Data Template configuration. This permission is not typically granted to users in a Production environment.
Shared Data Template DeleteAbility to delete an existing configuration for Shared Data TemplatesRequired by System Configuration users in lower-level environments to delete Shared Data Template configuration. This permission is not typically granted to users in a Production environment.
Shared Data Template ApproveAbility to approve a Risk model version that is submitted for publicationRequired by System Configuration users in lower-level environments to approve a Shared Data Template version. This permission is not typically granted to users in a Production environment.
Shared Data Template ArchiveAbility to archive a Shared Data Template version.Required by System Configuration users in lower-level environments to archive a Shared Data Template version. This permission is not typically granted to users in a Production environment.

Webhooks

Permission NameDescriptionNotes
Access to WebhookAbility to access the Webhooks UI.This is a requisite permission that must be assigned in order for the user to access the Webhooks UI. This permission it typically provided to a configuration user in a lower level environment or a Production Support user in Production.
Manage WebhookAbility to create, edit and delete WebhooksRequired by System Configuration users in lower-level environments to create, edit and delete Webhook configuration. This permission is typically granted to specifed technical users in Production in order to set up Webhooks in that environment.

Operational Permissions

Association

Permission NameDescriptionNotes
Association AccessAbility to view the Hierarchy graphical representation within the UIUsers with this permission will be able to view an entity's associations with other entities. This will allow them to see an entity's hierarchy and related parties in the relevant screens.
Association EditAbility to add or edit an entity associationUsers with this permission will have the ability to create and edit a draft association only. In order to verify/approve the associations, they need "Association Verification" permission.
Association DeleteAbility to delete an entity associationUsers with this permission will have the ability to delete a draft association or to mark a verified association for deletion. In order to verify/approve the associations, they need "Association Verification" permission.
Association Edit & DeleteAbility to interact with (add/edit/remove) the association graphical representation within the UI.Users with this permission will have the ability to create, edit and delete a draft association or to mark a verified association for deletion - ultimately, they will have the ability to interact with the related parties grid in the Related Parties task. To verify/approve the associations, they need "Association Verification" permission. Previously this permission was labelled as "Association Edit"
Association Edit & Partial DeleteAbility to interact with (add/edit/remove) the association graphical representation within the UI, without the ability to remove ALL associations between a source and target entity.This permission is identical to Association Edit & Delete in terms of API permissions, however in the UI it does not include the ability to remove all associations between a source and target entity.
Association Edit & Link OnlyAbility to add entity associations but only link to existing entities, restricting the ability to create new entities as part of the process.Users granted with this permission AND not granted with "Association Edit", "Association Edit & Delete" or "Association Edit & Partial Delete", will have the ability to create new associations but will not see the 'Create New' option within the modal and therefore can only link to existing entities returned by the Search.
Association VerificationAbility to overwrite a verified record's hierarchy from a newer draft's versionUsers with this permission will have the ability to set a draft association to be verified. When the feature is available, it will also allow them to manage any conflict between draft and verified associations and resolve these before verifying associations in a journey.

Audit

Permission NameDescriptionNotes
Audit Access & SearchAbility to access and search from the Audit Trail feature (both Entity and Journey level)Typically assigned to operational users who are entitled to review the Audit history of an entity or journey

Comments

Permission NameDescriptionNotes
Access to CommentsAbility to access Comments (launch the Comments shelf)This permission allows users to access the comments shelf wherever it is contained in the system (e.g. from within a Journey). This permission is typically provided to operational users who are responsible for working on Clients and are permitted to view Comments.
Create a Comment ThreadAbility to create a new Comment thread (create a new comment)This permission allows users to create new Comments from any of the contexts where the Comments shelf is contained. This permission is typically provided to operational users who are responsible for working on Clients, are permitted to view Comments and are expected to leave Comments related to the Client.
Delete Any CommentAbility to delete any Comment or Reply to a Comment (made by any user)This permission allows users to Delete any Comment or Reply to a Comment within Fenergo SaaS. This permission is typically reserved to trusted users who are permitted to remove Comments or Replies that were created by other Users.
Delete Your Own CommentsAbility to delete Comments or Replies that you createdThis permission allows users to Delete any Comment or Reply to a Comment within Fenergo SaaS. This permission is typically provided to all users who are responsible for working on Clients, are permitted to view Comments and are expected to leave Comments related to the Client so that they can remove a comment created in error.
Reply to a Comment ThreadAbility to Reply to a Comment threadThis permission allows users to Reply to any Comment thread from any of the contexts where the Comments shelf is contained. This permission is typically provided to operational users who are responsible for working on Clients, are permitted to view Comments and are expected to Reply to Comments related to the Client.

Conflict Resolution

Permission NameDescriptionNotes
Conflict Resolution AccessAbility to access the conflict resolution taskUsers with this entity permission will be able to open the conflict resolution task that is in a journey.
Conflict Resolution EditAbility to access, review & select the coorect data to resolve the conflicts inside the taskUsers with this permission will be able to use the radio buttons in the data conflict task to select which data they want to take into the entity draft. Users will need to have the conflict resolution access permission to use this one.
Product Conflict Resolution AccessAbility to access the Products tab in the Conflict Resolution taskUsers with this product permission will be able to view the detail in the Products tab within the Conflict Resolution task that is in a journey.
Product Conflict Resolution EditAbility to select the correct data and resolve the product conflicts inside the Products tab of the taskUsers with this permission will be able to use the radio buttons in the Products tab of the Conflict Resolution task to select which data they want to take into the product draft and to resolve the product conflict detected. Users will need the Product Conflict Resolution Access permission to use this permission.

Dashboards

Permission NameDescriptionNotes
Task Dashboard AccessAbility to access the Task Dashboard in the UIUsers with this permission will be able to view and interact with the Task Dashboard. This permission is typically provided to all operational users involved with CLM activities within the system.
Team Management Dashboard AccessAbility to access the Team Management Dashboard in the UIUsers with this permission will be able to view and interact with the Team Management Dashboard. This permission is typically provided to operational users with workload management and tracking responsibilities.
Data Protection Dashboard AccessAbility to Access the Data Protection DashboardThis permission allows users to access the Data Protection dashboard which is used to review and action entities that have been identified in the system through an Entity Check. This permission is typically provided to operational users who are responsible for Offboarding entities in the system.

Digital ID&V

Permission NameDescriptionNotes
Digital ID&V AccessAbility to open the Fenergo Native Digital ID&V task or view the Digital ID&V panel when working with AssociationsUsers with this permission can access and view the results of the Fenergo Native Digital ID&V task and view the digital ID&V panel when interacting with associations.
Digital ID&V Approve Or RejectAbility to approve or reject an ID&V resultUsers with this permission can select the Approve or Reject button in the Fenergo Native ID&V task and provide commentary to support their decision.
Digital ID&V CreateAbility to initiate the Digital ID&V request from Fenergo SaaS to JumioUsers with this permission will be initiate a Digital ID&V request to Jumio and will be able to complete the Digital ID&V steps on Fenergo SaaS.

Document Management

Permission NameDescriptionNotes
Document Management AccessAbility to access the document task and view documentsUsers with this permission will be able to see all document requirements and linked documents for any entity they have access to. They will also be able to view a document's metadata and open the document viewer to see the document itself.
Document Management CreateAbility to upload documents, add metadata, and submit a request for approval/waive/deferralUsers with this permission will be able to upload a document and populate any document metadata as part of the upload process. Additionally they will be able to update the document requirement status to Pending, Approval, Waive Requested or Deferral Requested.
Document Management EditAbility to edit document metadataUsers with this permission will be able to edit the metadata of an existing document.
Document Management DeleteAbility to delete documentsUsers with this permission will be able to delete a document which has previously been uploaded.
Document Management ApproveAbility to approve or reject document requirementsUsers with this permission will be able to Approve or Reject any documents requirements with a status of Pending Approval, or Reject any documents with a status of Waive Requested or Deferral Requested.
Document Management Defer or WaiveAbility to defer or waive document requirementsUsers with this permission will be able to Approve any document requirements with a status of Waive Requested or Deferral Requested. In order to Reject document requirements with these statuses, the user must have the Document Management Approve status.
Document Management Send for SignatureAbility to request signature for document requirementsUsers with this permission will be able request eSignature for any document requirement. This permission should not be used when eSignature is not enabled for a client's tenant.

Entity Data

Permission NameDescriptionNotes
Entity Data Access & SearchAbility to search and access entity recordsRequired for all operational users who are involved with CLM activities within the system.
Entity Data EditAbility to create and edit entity draft recordsRequired for operational users who will be starting new journeys or editing entity data in a journey.
Entity Data ApproveAbility to approve or reject entity drafts to create new verified entitiesRequired for operational users who are involved in approving or rejecting the entity draft records at the end of a journey.
Change Entity Draft Access LayersAbility to modify the Access Layers of an entity, as seen in the Journey Hub under the 'Change Entity Draft Access Layer' optionRequired for users who are authorized to modify Access Layers on an entity. Note, an Entity can only have it's Access Layers modified from an in-progress Journey from interacting with the 'three dots' action button

Entity Group Management

Permission NameDescriptionNotes
Entity Group Management Access & SearchAbility to search and access entity group recordsRequired for all operational users who are involved with managing and interacting with entity groups within the system.
Entity Group Management EditAbility to create and edit entity group recordsRequired for operational users who will be creating new Groups responsible for editing groups.

External Data

Permission NameDescriptionNotes
External Data AccessAbility to view the External Data results from the External Data ProviderUsers with this permission will be able to view the search results within the External Data task and be able to select an entity they wish to request the full profile for.
External Data ApproveAbility to initiate the Import of entities/data from the External Data Provider to Fenergo SaaSUsers with this permission will be able to Import records from the External Data provider to Fenergo SaaS.

ID&V

Permission NameDescriptionNotes
ID&V AccessAbility to view the section containing ID&V fields within the UIRequired for all operational users who are involved with ID&V related CLM activities within the system.
ID&V EditAbility to edit the fields within the ID&V section in the UIRequired for all operational users who are involved with ID&V related CLM activities within the system.
ID&V DeleteAbility to delete values from the ID&V section in the UIRequired for all operational users who are involved with ID&V related CLM activities within the system.

Integration Flows

Permission NameDescriptionNotes
Flow Task RetryAbility to rerun a failed Flow Execution from the Flow Journey TaskRequired by users who are authorized to retry a Flow Execution from within a Journey.
Flow Task CloseAbility to close Flow Journey TaskRequired by users who are authorized to manually close a Journey in the event that the execution fails. Normally the Flow task would automatically closed by the execution completing successfully. In some scenarios it may be necessary to manually bypass a failing integration. Consider assigning to an elevated users.
Flow Execution ReadAbility to view the Flow tab in Integration HubThis permission allows users to review Flow Executions in Integration Hub. Users who don't have this permission will not see the Flows tab.
Flow Execution Details ReadAbility to view Flow Execution Details from Integration Hub or Flow StudioThis permission allows users to access the Execution Details page to review attempts, Step Logs, and Flow Logs.
Flow API TriggerAbility to initiate an API FlowThis permission is required to trigger an API Flow either via the 'Execute' button in FlowStudio -> Flow -> Executions tab, or directly via the API. Note - this does not affect Flows triggered via the Custom Auth API Endpoint.
Persisted Storage AccessAbility to access Persisted Storage tab and list filesThis permission is required to view the list of files stored on disk.
Persisted Storage Get RecordAbility to view the contents of a NotSensitive file.This permission is required to view contents of files marks as 'NotSensitive'.
Persisted Storage Get Sensitive RecordAbility to view the contents of a Sensitive file.This permission is required to view contents of files marks as 'Sensitive'. Sensitive files contain sensitive data, consider assigning this to an elevated user who should have access to sensitive data.
Persisted Storage Delete RecordAbility to delete a file in Storage.This permission is required to delete a file from the Persisted Flows tab in Flow Studio.

Journey

Permission NameDescriptionNotes
Journey AccessAbility to access an instance of a journey, to be able to view the Journey Hub and interact with the tasks that make it upRequired for all operational users who are involved with CLM activities within the system.
Journey CancelAbility to cancel a journey, as seen in the Journey Hub as the 'Cancel Journey' option from interacting with the 'three dots' action buttonRequired for users who are authorized to cancel a Journey.
Journey EditAbility to Complete tasksThis is separate to permissions for process screening or update client data. For those, we are updating data within the relevant domain. This permission allows us to update the task itself (i.e., to change the task status).
Journey CreateAbility to access the New Request screen to create a Journey and the ability to interact with the Launch Journey button in the UIProvisioned to all operational users requiring the ability to initiate Journeys on entities in the system.
Completed Task AccessAbility to access a completed task within a Journey regardless of the Team the task is assigned toProvisioned to operational users requiring access to review previously completed tasks that are assigned to a Team that the user is not a member of. This permission is typically provided to Audit, QC, QA Teams.
Journey Reassign Task Owner & TeamAbility to reassign the Team and Owner of a Task within the Journey HubProvisioned to operational users requiring the ability to reassign the assigned Team and Owner of tasks within a journey. In some circumstances an organization may wish to restrict this permission only to trusted users. Note, a user requires access to the team that the task is assigned to in order to reassign the task. Previously, this permission was labelled as "Task Reassign".
Journey Reassign Read Only TaskAbility to reassign the Team and Owner of a Task within the Journey Hub while having read only access to the Task.Provisioned to operational users requiring the ability to reassign the assigned Team and Owner of tasks within a journey but can only view the task in a read-only format. In some circumstances an organization may wish to restrict this permission only to trusted users. Note, a user requires access to the team that the task is assigned to in order to reassign the task. Previously, this permission was labelled as "Task Reassign".
Journey Reassign Task Owner OnlyAbility to reassign the Owner of a Task within the Journey HubProvisioned to operational users who are required to only have the ability to assign or reassign the Owner of tasks within a journey. In some circumstances an organization may wish to restrict this permission only to trusted users. Note, a user requires access to the team that the task is assigned to in order to reassign the task.
Journey Reassign Task Owner, No Task AccessAbility to reassign the Owner of a Task within the Journey Hub, without having the ability to click into that task and see the dataProvisioned to operational users who are required to only have the ability to assign or reassign the Owner of tasks within a journey but do not have permission to view the Entity Data being captured within that Task in the Journey.
Journey Reopen TaskAbility to reopen a completed task within an active journeyProvisioned to operational users requiring the ability to reopen completed tasks within a journey. In some circumstances an organization may wish to restrict this permission only to trusted users.
Change Journey Access LayersAbility to modify the Access Layers of a journey, as seen in the Journey Hub under the 'Change Journey Access Layer' option from interacting with the 'three dots' action buttonRequired for users who are authorized to modify Access Layers on an in-progress Journey. Note, a Journey can only have it's Access Layers modified when it is in -progress Journey.
Journey Pause TaskAbility to Pause a Task in the Journey HubThis permission allows users to pause and unpause a Task that is in progress and has SLA configuration against it. This permission is typically provided to operational users who are responsible for working on Clients, and that require the ability to pause a Task to prevent the SLA being breached.
Journey Pause StageAbility to Pause a Stage in the Journey HubThis permission allows users to pause and unpause a stage that is in progress and has SLA configuration against it. This permission is typically provided to operational users who are responsible for working on Clients, and that require the ability to pause a Stage to prevent the SLA being breached.
Journey Pause InstanceAbility to Pause a Journey in the Journey HubThis permission allows users to pause and unpause a Journey that is in progress and has SLA configuration against it. This permission is typically provided to operational users who are responsible for working on Clients, and that require the ability to pause a Journey to prevent the SLA being breached.

Lookup

Permission NameDescriptionNotes
Lookup AccessAbility to return Lookup values in the systemProvisioned to all operational users requiring List of Value dropdowns to be returned in the UI. Provisioned to all configuration users requiring List of Value dropdowns to be returned in the UI for the purpose of configuration. Generally provided to all system users unless an organization has a specific user class that is not required to see any entity data within the application (e.g. Application Support Teams).

Policy Search and Journey

Permission NameDescriptionNotes
Policy Search and Requirement ScopeAbility to view and interact with the policy requirements in scope for a journeyProvisioned to all operational users requiring policy driven attributes to be returned in the UI. Generally provided to all system users unless an organization has a specific user class that is not required to see any entity data within the application (e.g., Application Support Teams).

Product

Permission NameDescriptionNotes
Product Access & SearchAbility to search and access product recordsRequired for all operational users who are involved with CLM (Client Lifecycle Management) activities within the system.
Product ApproveAbility to approve or reject product drafts and to create new verified entities.Required for operational users who are involved in approving or rejecting product records at the end of a journey.
Product EditAbility to create and edit product draft recordsRequired for operational users who will be editing a product in a journey.
Product OffboardingAbility to select an active product for offboard, or an offboarded product for re-onboard, and creates a new draft record.Required for operational users who will be marking products as end of life within a journey, or returning a product from offboarded status within a journey.
Product Requirement ScopeAbility to view and interact with the requirements in scope.Required for operational users who are interacting with products in a journey and will not have configuration permissions.

Proposed Changes

Permission NameDescriptionNotes
Proposed Changes AccessAbility to access the Proposed Changes taskProvisioned to operational users required to interact with the Proposed Changes task in the journey. Generally provided to all operational users.
Proposed Changes EditAbility to make changes by selecting desired data to proceed with during the Proposed Changes taskProvisioned to operational users trusted to apply data decisions within the Proposed Changes task in the journey.

Reporting

Permission NameDescriptionNotes
Reporting AccessAllows users to access Advanced Reporting and Legacy Reporting. For advanced reporting, they can see saved queries and the SQL behind them. For legacy reporting, they can run all OOTB reports.This permission covers all functionality available in legacy reporting. This permission is typically provided to users who wish to interact with the Reporting feature from the UI. A user with this permission can generate all the available canned reports and access the Advanced Reporting feature.
Reporting EditAbility to create, edit, preview and save queries in the Advanced Reporting featureThis permission is typically provided to users trusted to interact with the Advanced Reporting feature from the UI. A user with this permission can make changes to any existing saved query. This permission does not allow users to execute reports.
Reporting DeleteAbility to delete saved queries in the Advanced Reporting featureThis permission is typically provided to users trusted to interact with the Advanced Reporting feature from the UI. A user with this permission can delete any existing saved query.
Reporting ExecuteAbility to execute (run) saved queries and download reports in the Advanced Reporting featureThis permission is typically provided to users trusted to interact with the Advanced Reporting feature from the UI. A user with this permission can also preview reports before they are run.

Risk

Permission NameDescriptionNotes
Risk Calculator AccessAbility to access and interact with the Risk Calculator featureThis permission is typically provided to users who wish to interact with the Risk Calculator from the UI. This permission is also required by services for engaging the Risk Calculate Endpoint.

Screening

Permission NameDescriptionNotes
Screening AccessAbility to view screening data results within a screening taskProvisioned to all operational users requiring the ability to resolve screening results and set outcomes. Note: A user also requires the appropriate Journey Permissions to interact with screening tasks within a journey.
Screening EditAbility to set match resolution status, edit comments, and set materiality assessment fields within screening tasksProvisioned to all operational users requiring the ability to resolve screening results and set outcomes. Note: A user also requires the appropriate Journey Permissions to interact with screening tasks within a journey.
Screening CreateAbility to create a new screening batch requestThis permission is only applicable to the /api/batch endpoints and is not part of the front end user experience. Screening requests are automatically created by a system task as part of a journey.
Screening DeleteAbility to delete an existing screening batchThis permission is only applicable to the /api/batch endpoints and is not part of the front end user experience.
Screening ApproveAbility to approve or reject screening escalation tasksThe purpose of this permission is to offer a higher level of Approval for adjudicating and approving Screening decisions. This permission is not leveraged in baseline configuration.

Transaction Monitoring

Permission NameDescriptionNotes
Alert Configuration AccessAbility to access the Alert Configuration Feature.Required by administrator to access the alert metadata.
Alert Configuration EditAbility to edit the Alert Configuration Feature.Required by administrator to update the alert metadata.
Alert Configuration ApproveAbility to approve an Alert Configuration.Required by system configuration to approve updates to the alert metadata.
Alert Dashboard AccessAbility to access the Alert Dashboard page.This permission will allow a user to see the Alert dashboard.
Alert Dashboard Configuration EditAbility to edit the Alert Dashboard columns- pending.
Alert AccessAbility to access the alert.This will allow a TM analyst to click through to an alert and see the details and transactions.
Whitelist AccessAbility to access the entity whitelist.This will give a user access to the Entity Whitelist.
Whitelist EditAbility to edit an entity whitelist entry.This will allow a user to add to or update the Entity Whitelist.
Whitelist DeleteAbility to delete an entity whitelist entry.This will allow a user to remove a whitelist record.
Whitelist ApproveAbility to approve an entity whitelist entry.This is required by users who should approve a whitelist added for an entity.
Entity Profile Transaction viewAbility to view transaction details for an entity.This will allow a user to see all the transaction for an entity.
Transactions Api AccessAbility to use transactions api.This allows a user to use the transaction API.
TM Risk Configuration EditAbility to edit risk configuration.Required by system configuration to update the TM risk configuration.
TM Risk Configuration AccessAbility to access risk configuration.Required by system configuration to access the TM risk configuration.
TM Risk Configuration ApproveAbility to approve risk configuration.Required by administrator to approve the risk configuration, not typically granted to users in Production environment.