Overview
The user privilege model specifies the functionality available to different user types throughout the system, defined by the following user roles:
Administrative Roles
Legacy Administrator - combines the privileges of the Provisioning Administrator and the Business Administrator, providing full day-to-day administrative control.
Provisioning Administrator - is designed to manage users, Single Sign-On, IP address allow lists, and grant Just-In-Time access whilst having no access to the platform's services and financial data:
Users: Provisioning Administrators can view/create/modify/delete users.
SSO Settings: Provisioning Administrators can view/create/modify/delete Single Sign-On configuration.
Grant Access: Provisioning Administrators can grant Support access to a client's environment through the Just-In-Time mechanism.
Business Administrator - is designed to manage all facets of the platform, except user management and single sign-on. This role can also grant Just-In-Time access to the necessary Support team.
Compliance & Operations Roles
Front Office - this role was specifically designed for our client's front-office users. Front Office users can log in to the platform, but will only have access to our Pre-Trade functionality. This role can only be created by clients who are signed up to our Pre-Trade service.
Reviewer - access to results, which includes the ability to assign & comment. Also able to view portfolios, individual rules, value sets and regulatory data. Designed for basic-level access.
Manager - same functionality as Reviewer, but with the ability to upload positions. Also able to view properties and data views, allowing rule analysis. Designed as the standard role for compliance users.
Technical & Integration Roles
API - an API-specific role designed for logging in via our API endpoints. It allows uploading data and receiving status responses. API users cannot log in to the UI platform.
Tech User - this role was specifically designed for IT teams. Tech users can log in and perform technical tasks, but cannot take action on the results. This includes managing the IP address allowed list.
Managing Users
The following article outlines the steps a Legacy or Provisioning Administrator should take to create, edit, or deactivate users.
Privilege Matrix
Legacy Administrator
Area | Actions Available |
Audit Trail | View, configure audit log streaming |
Companies | View, create, edit, delete |
Data Overrides | View, create, edit |
Data Provider Settings | Create, edit |
Data Views | View |
Disaggregations | View |
Disclosures | Generate, disclose, mark as filed |
Filing Manager | View, download, submit |
Global Company Database (GCD) | View |
Global Settings | View, edit, change warning % |
IP Address Allowed List | Add, remove (requests need to be made through Support) |
ISIN Screening | View, submit |
Issuer Requests | General |
Portfolios | View, upload, download, create, edit, assign rule folders, assign aggregations, set warning % |
Pre-Trade Check | View, submit |
Pre-Trade Data Enrichment | View, submit |
Properties | View |
Regulatory Data | View |
Regulatory Reporting | View, edit, approve fields, create reports, generate submission documents |
Reporting | View |
Results | View, post comments, assign/take, verify/reject |
Rules | View, approve, deactivate, set warning % |
SFTP Configuration | View setup details and configure/edit file delivery schedules |
Single Sign-On | View, create, edit, delete SSO configuration |
Support Access | Grant Just-In-Time access to Support |
Tasks | View, assign, confirm |
Transactions | Import, download |
Uploads | View previous uploads; import positions via UI only |
Users | View, create, edit, delete users |
Value Sets | View |
Provisioning Administrator
Area | Actions Available |
IP Address Allowed List | Add, remove (requests need to be made through Support) |
SFTP Configuration | View setup details and configure/edit file delivery schedules |
Single Sign-On | View, create, edit, delete SSO configuration |
Support Access | Grant Just-In-Time access to Support |
Users | View, create, edit, delete users |
Business Administrator
Area | Actions Available |
Audit Trail | View, configure audit log streaming |
Companies | View, create, edit, delete |
Data Overrides | View, create, edit |
Data Views | View |
Disaggregations | View |
Disclosures | Generate, disclose, mark as filed |
Filing Manager | View, download, submit |
Global Company Database (GCD) | View |
Global Settings | View, edit, change warning % |
ISIN Screening | View, submit |
Issuer Requests | General access |
Portfolios | View, upload, download, create, edit, assign rule folder, assign aggregation, set warning % |
Pre-Trade Check | View, submit |
Pre-Trade Data Enrichment | View, submit |
Properties | View |
Regulatory Data | View |
Regulatory Reporting | View, edit, approve fields, create reports, generate submission documents |
Reporting | View |
Results | View, post comments, assign/take, verify/reject |
Rules | View, approve, deactivate, set warning % |
SFTP Configuration | View setup details and Configure/Edit file delivery schedules |
Support Access | Grant Just-In-Time access to Support |
Tasks | View, assign, confirm |
Transactions | Import, download |
Uploads | View previous uploads; import positions via the UI only |
Value Sets | View |
Front Office
Area | Actions Available |
ISIN Screening | View, submit |
Pre-Trade Check | View, submit |
Pre-Trade Data Enrichment | View, submit |
Manager
Area | Actions Available |
Companies | View |
Data Overrides | View |
Data Views | View |
Disclosures | Generate, disclose, mark as filed |
Filing Manager | View, download, submit |
Global Company Database (GCD) | View |
ISIN Screening | View, submit |
Issuer Requests | General access |
Portfolios | View, upload, download |
Pre-Trade Check | View, submit |
Pre-Trade Data Enrichment | View, submit |
Properties | View |
Regulatory Data | View |
Regulatory Reporting | View, edit, approve fields, create reports, generate submission documents |
Reporting | View |
Results | View, post comments, assign/take, verify/reject |
Tasks | View, assign |
Transactions | Import, download |
Uploads | Import positions |
Value Sets | View |
Reviewer
Area | Actions Available |
Companies | View |
Data Overrides | View |
Data Views | View |
Filing Manager | View |
Global Company Database (GCD) | View |
ISIN Screening | View, submit |
Portfolios | View, download |
Pre-Trade Check | View, submit |
Pre-Trade Data Enrichment | View, submit |
Properties | View |
Regulatory Data | View |
Regulatory Reporting | View, edit, approve fields, create reports, generate submission documents |
Reporting | View |
Results | View, post comments, assign/take |
Tasks | View, assign |
Transactions | View |
Value Sets | View |
Tech User
Area | Actions Available |
Audit Trail | View, configure audit log streaming |
Data Overrides | View |
Data Provider Settings | Create, edit |
IP Address Allowed List | Add, remove (requests need to be made through Support) |
SFTP Configuration | View setup details only |
Single Sign-On | View, create, edit, delete SSO configuration |
Transactions | Import, download |
Uploads | View previous uploads |
API User
Area | Actions Available |
Status Responses | Receive upload and processing responses |
Transactions | Import |
Uploads | Import positions via API only |