Permissions
Every permission-grantable feature across the platform, generated directly from the permissions registry — this page can never drift from what a Team & Permissions page can actually grant. Each feature can be granted independently per action (VIEW, INITIATE, APPROVE, PUBLISH) — a grant is stored as feature:ACTION, e.g. payments.invoices:APPROVE.
Treasury
| Feature | Name | What it gates |
|---|---|---|
treasury.dashboard | Dashboard | View the org-wide portfolio dashboard. |
treasury.wallets | Wallets | View and manage every wallet across the whole org (Treasury's is the only wallet feature that gates both reads and writes). `PUBLISH` on this feature also doubles as the platform-wide high-trust gate for actually signing transactions — Desktop Signer device pairing, Connect Wallet signing, and the final step of cross-domain approval chains all require it. |
treasury.treasury | Transfers | Create and manage internal transfers between the org's own wallets. |
treasury.approvals | Approvals | Act on treasury-level approval requests. |
treasury.policies | Policies | Create/edit/delete any policy, including cross-cutting ones spanning multiple apps — the only place cross-cutting policies can be managed. |
treasury.address-book | Address Book | Manage the org-wide verified address book used by policy whitelist rules. |
treasury.compliance | Compliance | View and resolve compliance cases across every app. |
treasury.reports | Reports | View org-wide treasury reporting and exports. |
treasury.ai | AI Insights | Use Treasury's AI-generated portfolio insights. |
treasury.developer | Developer | Manage API keys, webhooks, and OAuth clients scoped to Treasury. |
treasury.organization | Organization Settings | Edit the organization's top-level settings (name, slug, plan, display currency). |
treasury.team | Team & Permissions | Invite/remove teammates and edit their Treasury permission grants. `PUBLISH` is what lets a member manage this page at all. |
Pay
| Feature | Name | What it gates |
|---|---|---|
payments.payments | Pay | Create, submit, and view outgoing payments (crypto and Stripe). |
payments.payment-methods | Payment Methods | View the wallets/cards available to pay from — also gates reading Payments' wallets (see `payments.wallets` for writes). |
payments.wallets | Wallets | Import, edit, or remove wallets from within Payments. Reads are gated separately by `payments.payment-methods`. |
payments.policies | Policies | Create/edit/delete spending policies scoped only to Payments — cross-cutting policies can only be managed from Treasury. Every policy affecting Payments is still visible here regardless of who can edit it. |
payments.vendors | Vendors | Manage the vendor directory used when creating payments. |
payments.products | Products | Manage the product catalog used by payment links and invoices. |
payments.payment-links | Payment Links | Create and manage shareable checkout links. |
payments.orders | Orders | View and manage incoming orders and their payment attempts. |
payments.invoices | Invoices | Create, send, and mark invoices paid. |
payments.customers | Customers | Manage the customer directory. |
payments.approvals | Approvals | Act on payments awaiting approval in a maker-checker chain. The chain's final (highest-trust) step additionally requires `treasury.wallets:PUBLISH`. |
payments.compliance | Compliance | View and resolve compliance cases opened against Payments transactions. |
payments.reports | Reports | View Payments reporting and exports. |
payments.developer | Developer | Manage API keys, webhooks, and OAuth clients scoped to Payments. |
payments.organization | Organization Settings | Edit Payments' organization-level settings (branding, currency, etc). |
payments.team | Team & Permissions | Invite/remove teammates and edit their Payments permission grants. `PUBLISH` is what lets a member manage this page at all. |
Trade
| Feature | Name | What it gates |
|---|---|---|
trade.business | Trading | Create and view trade orders (Market/Limit/Exchange). Also gates reading Trade's wallets (see `trade.wallets` for writes). |
trade.wallets | Wallets | Import, edit, or remove wallets from within Trade. Reads are gated separately by `trade.business`. |
trade.policies | Policies | Create/edit/delete spending policies scoped only to Trade — cross-cutting policies can only be managed from Treasury. Every policy affecting Trade is still visible here regardless of who can edit it. |
trade.approvals | Approvals | Act on trade orders awaiting approval in a maker-checker chain. The chain's final (highest-trust) step additionally requires `treasury.wallets:PUBLISH`. |
trade.compliance | Compliance | View and resolve compliance cases opened against Trade orders. |
trade.reports | Reports | View Trade reporting and exports. |
trade.developer | Developer | Manage API keys, webhooks, and OAuth clients scoped to Trade. |
trade.organization | Organization Settings | Edit Trade's organization-level settings. |
trade.team | Team & Permissions | Invite/remove teammates and edit their Trade permission grants. `PUBLISH` is what lets a member manage this page at all. |
Earn
| Feature | Name | What it gates |
|---|---|---|
earn.business | Deposits & withdrawals | Create and view earn orders (deposit/withdraw/claim). Also gates reading Earn's wallets (see `earn.wallets` for writes). |
earn.wallets | Wallets | Import, edit, or remove wallets from within Earn. Reads are gated separately by `earn.business`. |
earn.policies | Policies | Create/edit/delete spending policies scoped only to Earn — cross-cutting policies can only be managed from Treasury. Every policy affecting Earn is still visible here regardless of who can edit it. |
earn.approvals | Approvals | Act on earn orders awaiting approval in a maker-checker chain. The chain's final (highest-trust) step additionally requires `treasury.wallets:PUBLISH`. |
earn.compliance | Compliance | View and resolve compliance cases opened against Earn orders. |
earn.reports | Reports | View Earn reporting and exports. |
earn.developer | Developer | Manage API keys, webhooks, and OAuth clients scoped to Earn. |
earn.organization | Organization Settings | Edit Earn's organization-level settings. |
earn.team | Team & Permissions | Invite/remove teammates and edit their Earn permission grants. `PUBLISH` is what lets a member manage this page at all. |
Borrow
| Feature | Name | What it gates |
|---|---|---|
borrow.business | Borrow & repay | Create and view borrow orders (borrow/repay/supply/withdraw collateral). Also gates reading Borrow's wallets (see `borrow.wallets` for writes). |
borrow.wallets | Wallets | Import, edit, or remove wallets from within Borrow. Reads are gated separately by `borrow.business`. |
borrow.policies | Policies | Create/edit/delete spending policies scoped only to Borrow — cross-cutting policies can only be managed from Treasury. Every policy affecting Borrow is still visible here regardless of who can edit it. |
borrow.approvals | Approvals | Act on borrow orders awaiting approval in a maker-checker chain. The chain's final (highest-trust) step additionally requires `treasury.wallets:PUBLISH`. |
borrow.compliance | Compliance | View and resolve compliance cases opened against Borrow orders. |
borrow.reports | Reports | View Borrow reporting and exports. |
borrow.developer | Developer | Manage API keys, webhooks, and OAuth clients scoped to Borrow. |
borrow.organization | Organization Settings | Edit Borrow's organization-level settings. |
borrow.team | Team & Permissions | Invite/remove teammates and edit their Borrow permission grants. `PUBLISH` is what lets a member manage this page at all. |