MOONEUM

Permissions

Every permission-grantable feature across the platform, generated directly from the permissions registry — this page can never drift from what a Team & Permissions page can actually grant. Each feature can be granted independently per action (VIEW, INITIATE, APPROVE, PUBLISH) — a grant is stored as feature:ACTION, e.g. payments.invoices:APPROVE.

Treasury

FeatureNameWhat it gates
treasury.dashboardDashboardView the org-wide portfolio dashboard.
treasury.walletsWalletsView and manage every wallet across the whole org (Treasury's is the only wallet feature that gates both reads and writes). `PUBLISH` on this feature also doubles as the platform-wide high-trust gate for actually signing transactions — Desktop Signer device pairing, Connect Wallet signing, and the final step of cross-domain approval chains all require it.
treasury.treasuryTransfersCreate and manage internal transfers between the org's own wallets.
treasury.approvalsApprovalsAct on treasury-level approval requests.
treasury.policiesPoliciesCreate/edit/delete any policy, including cross-cutting ones spanning multiple apps — the only place cross-cutting policies can be managed.
treasury.address-bookAddress BookManage the org-wide verified address book used by policy whitelist rules.
treasury.complianceComplianceView and resolve compliance cases across every app.
treasury.reportsReportsView org-wide treasury reporting and exports.
treasury.aiAI InsightsUse Treasury's AI-generated portfolio insights.
treasury.developerDeveloperManage API keys, webhooks, and OAuth clients scoped to Treasury.
treasury.organizationOrganization SettingsEdit the organization's top-level settings (name, slug, plan, display currency).
treasury.teamTeam & PermissionsInvite/remove teammates and edit their Treasury permission grants. `PUBLISH` is what lets a member manage this page at all.

Pay

FeatureNameWhat it gates
payments.paymentsPayCreate, submit, and view outgoing payments (crypto and Stripe).
payments.payment-methodsPayment MethodsView the wallets/cards available to pay from — also gates reading Payments' wallets (see `payments.wallets` for writes).
payments.walletsWalletsImport, edit, or remove wallets from within Payments. Reads are gated separately by `payments.payment-methods`.
payments.policiesPoliciesCreate/edit/delete spending policies scoped only to Payments — cross-cutting policies can only be managed from Treasury. Every policy affecting Payments is still visible here regardless of who can edit it.
payments.vendorsVendorsManage the vendor directory used when creating payments.
payments.productsProductsManage the product catalog used by payment links and invoices.
payments.payment-linksPayment LinksCreate and manage shareable checkout links.
payments.ordersOrdersView and manage incoming orders and their payment attempts.
payments.invoicesInvoicesCreate, send, and mark invoices paid.
payments.customersCustomersManage the customer directory.
payments.approvalsApprovalsAct on payments awaiting approval in a maker-checker chain. The chain's final (highest-trust) step additionally requires `treasury.wallets:PUBLISH`.
payments.complianceComplianceView and resolve compliance cases opened against Payments transactions.
payments.reportsReportsView Payments reporting and exports.
payments.developerDeveloperManage API keys, webhooks, and OAuth clients scoped to Payments.
payments.organizationOrganization SettingsEdit Payments' organization-level settings (branding, currency, etc).
payments.teamTeam & PermissionsInvite/remove teammates and edit their Payments permission grants. `PUBLISH` is what lets a member manage this page at all.

Trade

FeatureNameWhat it gates
trade.businessTradingCreate and view trade orders (Market/Limit/Exchange). Also gates reading Trade's wallets (see `trade.wallets` for writes).
trade.walletsWalletsImport, edit, or remove wallets from within Trade. Reads are gated separately by `trade.business`.
trade.policiesPoliciesCreate/edit/delete spending policies scoped only to Trade — cross-cutting policies can only be managed from Treasury. Every policy affecting Trade is still visible here regardless of who can edit it.
trade.approvalsApprovalsAct on trade orders awaiting approval in a maker-checker chain. The chain's final (highest-trust) step additionally requires `treasury.wallets:PUBLISH`.
trade.complianceComplianceView and resolve compliance cases opened against Trade orders.
trade.reportsReportsView Trade reporting and exports.
trade.developerDeveloperManage API keys, webhooks, and OAuth clients scoped to Trade.
trade.organizationOrganization SettingsEdit Trade's organization-level settings.
trade.teamTeam & PermissionsInvite/remove teammates and edit their Trade permission grants. `PUBLISH` is what lets a member manage this page at all.

Earn

FeatureNameWhat it gates
earn.businessDeposits & withdrawalsCreate and view earn orders (deposit/withdraw/claim). Also gates reading Earn's wallets (see `earn.wallets` for writes).
earn.walletsWalletsImport, edit, or remove wallets from within Earn. Reads are gated separately by `earn.business`.
earn.policiesPoliciesCreate/edit/delete spending policies scoped only to Earn — cross-cutting policies can only be managed from Treasury. Every policy affecting Earn is still visible here regardless of who can edit it.
earn.approvalsApprovalsAct on earn orders awaiting approval in a maker-checker chain. The chain's final (highest-trust) step additionally requires `treasury.wallets:PUBLISH`.
earn.complianceComplianceView and resolve compliance cases opened against Earn orders.
earn.reportsReportsView Earn reporting and exports.
earn.developerDeveloperManage API keys, webhooks, and OAuth clients scoped to Earn.
earn.organizationOrganization SettingsEdit Earn's organization-level settings.
earn.teamTeam & PermissionsInvite/remove teammates and edit their Earn permission grants. `PUBLISH` is what lets a member manage this page at all.

Borrow

FeatureNameWhat it gates
borrow.businessBorrow & repayCreate and view borrow orders (borrow/repay/supply/withdraw collateral). Also gates reading Borrow's wallets (see `borrow.wallets` for writes).
borrow.walletsWalletsImport, edit, or remove wallets from within Borrow. Reads are gated separately by `borrow.business`.
borrow.policiesPoliciesCreate/edit/delete spending policies scoped only to Borrow — cross-cutting policies can only be managed from Treasury. Every policy affecting Borrow is still visible here regardless of who can edit it.
borrow.approvalsApprovalsAct on borrow orders awaiting approval in a maker-checker chain. The chain's final (highest-trust) step additionally requires `treasury.wallets:PUBLISH`.
borrow.complianceComplianceView and resolve compliance cases opened against Borrow orders.
borrow.reportsReportsView Borrow reporting and exports.
borrow.developerDeveloperManage API keys, webhooks, and OAuth clients scoped to Borrow.
borrow.organizationOrganization SettingsEdit Borrow's organization-level settings.
borrow.teamTeam & PermissionsInvite/remove teammates and edit their Borrow permission grants. `PUBLISH` is what lets a member manage this page at all.