Standard Permission Set Reference

What each Modern Treasury standard permission set grants

Modern Treasury ships a set of standard (managed) permission sets. They cannot be edited, but they can be assigned to roles as-is or cloned as the starting point for a custom permission set.

This page lists every standard permission set and every standard role, the resources each covers, and the actions each allows, so you can tell what a set or role grants without assigning it first.

Actions use the same names as the dashboard: View, Create, Edit, Delete, plus Review (approve a payment order or external account) and Reconcile / Unreconcile (match or unmatch an expected payment).

Standard Roles at a Glance

Standard RoleStandard Permission Sets
AdministratorAdministrator
EngineeringDeveloper, API Manager
FinancePayments, Invoicing, Reconciliation Operations, FX
Finance ManagerAccounts Manager, Financial Controls

There is also an API Manage All role, which contains the API Manage All permission set and is assignable to API keys rather than users. The Ledgers, Ledger Viewer, and Finance Viewer permission sets are not part of any standard role and can be added to a role of your own.

Each role is broken down in Standard Roles in Detail below.

Choosing Between Similar Sets

Several resources appear in more than one standard permission set, at different access levels. The most common points of confusion:

  • Payment Flows vs. Payment Orders. Payment Flows are embeddable UI flows and belong to the Developer set. Payment orders — the instruction to move money — belong to Payments and Invoicing (create, view, edit, review), and are view-only in Financial Controls and Finance Viewer.
  • Expected Payments. Included in Reconciliation Operations (full access plus Reconcile and Unreconcile), Invoicing (view and create only), and Finance Viewer (view only). They are not part of the Payments set.
  • Internal Accounts. View-only in Reconciliation Operations, FX, and Finance Viewer; view and edit in Payments and Invoicing; full access in Accounts Manager and Financial Controls.
  • Ledger Transactions. Create, view, and edit in Payments, Invoicing, and Reconciliation Operations; full access in Ledgers; view-only in Ledger Viewer.
  • Sweep Rules appear in both Payments and Financial Controls with full access.

Standard Permission Sets

Administrator

Unrestricted access to every resource and action, including user management, roles, and permission sets. This is the only set that can administer access itself.

Grants: all actions on all resources.

Developer

Build and debug an integration with Modern Treasury: embeddable flows, publishable keys, webhook endpoints, request logs, and events. This is the set that contains Payment Flows — it does not grant access to payment orders, expected payments, or accounts.

ResourceActions
Account Collection FlowsView, Create, Edit, Delete
Bulk RequestsView
EventsView
Payment FlowsView, Create, Edit, Delete
Publishable KeysView, Create, Edit, Delete
Request LogsView
User Onboarding FlowsView, Create, Edit, Delete
Webhook EndpointsView, Create, Edit, Delete

Not included: Payment orders, expected payments, internal accounts, ledgers, and users.

API Manager

Create, view, and revoke API keys, and view the roles that can be assigned to them.

ResourceActions
API KeysView, Create, Edit, Delete
RolesView

Not included: Any payments, accounts, or ledger resource.

Reconciliation Operations

Reconcile expected payments against transactions, and record the ledger side of a match. This is the only standard set that grants the Reconcile and Unreconcile actions.

ResourceActions
Bank ConnectionsView
CounterpartiesView
Expected PaymentsView, Create, Edit, Delete, Reconcile, Unreconcile
Internal AccountsView
Ledger AccountsView, Create, Edit
Ledger TransactionsView, Create, Edit
LedgersView
Reconciliation GroupsView
Transaction Line ItemsView, Create, Edit, Delete
TransactionsView

Not included: Payment orders, invoices, and rules.

FX

Request and manage foreign exchange quotes.

ResourceActions
FX QuotesView, Create, Edit, Delete
Internal AccountsView

Not included: Payment orders and internal account changes.

Payments

Originate and manage payments end to end, along with the counterparty and external account data payments depend on. Note that it also grants full access to counterparties, sweep rules, returns, and reversals, and that it does not grant expected payments.

ResourceActions
Account Details for External AccountsView
Bank ConnectionsView
CounterpartiesView, Create, Edit, Delete
External AccountsView, Create, Edit, Delete, Review
File TransfersView
Incoming Payment DetailsView, Create, Edit, Delete
Internal AccountsView, Edit
Ledger AccountsView
Ledger TransactionsView, Create, Edit
LedgersView
Payment OrdersView, Create, Edit, Review
ReturnsView, Create, Edit, Delete
ReversalsView, Create, Edit, Delete
Sweep RulesView, Create, Edit, Delete

Not included: Expected payments, invoices, ledgers beyond ledger transactions, rules, and users.

Invoicing

Create, send, and collect invoices, including the payment orders and expected payments generated when an invoice is paid.

ResourceActions
CounterpartiesView
Expected PaymentsView, Create
External AccountsView
Internal AccountsView, Edit
InvoicesView, Create, Edit, Delete
Ledger Account SettlementsView, Edit
Ledger TransactionsView, Create, Edit
Payment OrdersView, Create, Edit, Review

Not included: Transactions, reconciliation actions, and rules.

Accounts Manager

Set up and maintain internal and virtual accounts and the transactions recorded against them.

ResourceActions
Internal AccountsView, Create, Edit, Delete
TransactionsView, Create, Edit, Delete
Virtual AccountsView, Create, Edit, Delete

Not included: Payment orders, expected payments, and ledgers.

Financial Controls

Configure the controls layer: payment approval rules, reconciliation rules, transaction categorization, internal account groups, and balance reports. Payment orders are view-only in this set.

ResourceActions
Balance ReportsView, Create, Edit, Delete
Bank ConnectionsView
Categorization MetadataView, Create, Edit, Delete
Internal Account GroupsView, Create, Edit, Delete
Internal AccountsView, Create, Edit, Delete
Payment Approval RulesView, Create, Edit, Delete
Payment OrdersView
Reconciliation RulesView, Create, Edit, Delete
Sweep RulesView, Create, Edit, Delete
Transaction Categorization RulesView, Create, Edit, Delete
User GroupsView
UsersView

Not included: Creating or approving payment orders.

Ledgers

Full read and write access to Ledgers, ledger accounts, ledger transactions, entries, categories, settlements, and statements.

ResourceActions
Ledger Account CategoriesView, Create, Edit, Delete
Ledger Account SettlementsView, Create, Edit, Delete
Ledger Account StatementsView, Create, Edit, Delete
Ledger AccountsView, Create, Edit, Delete
Ledger EntriesView, Create, Edit, Delete
Ledger TransactionsView, Create, Edit, Delete
LedgersView, Create, Edit, Delete

Not included: Payments, accounts, counterparties, and transactions.

Finance Viewer

View-only access across payments, accounts, counterparties, and transactions. Grants no write actions.

ResourceActions
Account Details for External AccountsView
Balance ReportsView
Bank ConnectionsView
CounterpartiesView
Expected PaymentsView
External AccountsView
Internal Account GroupsView
Internal AccountsView
Payment OrdersView
ReturnsView
ReversalsView
TransactionsView
Virtual AccountsView

Not included: Any create, edit, or delete action, and all ledger resources.

Ledger Viewer

View-only access across Ledgers and all ledger objects. Grants no write actions.

ResourceActions
Ledger Account CategoriesView
Ledger Account SettlementsView
Ledger Account StatementsView
Ledger AccountsView
Ledger EntriesView
Ledger Event HandlersView
Ledger TransactionsView
Ledgerable EventsView
LedgersView

Not included: Any create, edit, or delete action.

API Manage All

Unrestricted access for API key actors — the API key equivalent of Administrator. Only assignable to API keys, not to users.

Grants: all actions on all resources.

Standard Roles in Detail

Each standard role is a bundle of standard permission sets. Where sets overlap on a resource, the role grants the union of their actions — the tables below show that combined result.

Administrator

Full access to the platform, including user management, roles, and permission sets. Assigned to the default Administrators group.

Permission sets: Administrator

Grants: all actions on all resources.

Engineering

Everything needed to build and operate an integration, plus API key management. Grants no access to payments, accounts, or ledgers.

Permission sets: Developer, API Manager

ResourceActions
API KeysView, Create, Edit, Delete
Account Collection FlowsView, Create, Edit, Delete
Bulk RequestsView
EventsView
Payment FlowsView, Create, Edit, Delete
Publishable KeysView, Create, Edit, Delete
Request LogsView
RolesView
User Onboarding FlowsView, Create, Edit, Delete
Webhook EndpointsView, Create, Edit, Delete

Finance

Day-to-day finance operations: originating payments, invoicing, reconciliation, and FX. Because its four sets overlap, the role's effective access on a shared resource is the broadest level any one set grants — for example Internal Accounts end up View and Edit, and Ledger Transactions end up View, Create, and Edit.

Permission sets: Payments, Invoicing, Reconciliation Operations, FX

ResourceActions
Account Details for External AccountsView
Bank ConnectionsView
CounterpartiesView, Create, Edit, Delete
Expected PaymentsView, Create, Edit, Delete, Reconcile, Unreconcile
External AccountsView, Create, Edit, Delete, Review
FX QuotesView, Create, Edit, Delete
File TransfersView
Incoming Payment DetailsView, Create, Edit, Delete
Internal AccountsView, Edit
InvoicesView, Create, Edit, Delete
Ledger Account SettlementsView, Edit
Ledger AccountsView, Create, Edit
Ledger TransactionsView, Create, Edit
LedgersView
Payment OrdersView, Create, Edit, Review
Reconciliation GroupsView
ReturnsView, Create, Edit, Delete
ReversalsView, Create, Edit, Delete
Sweep RulesView, Create, Edit, Delete
Transaction Line ItemsView, Create, Edit, Delete
TransactionsView

Finance Manager

Account setup and the controls layer: internal and virtual accounts, transactions, approval and reconciliation rules, categorization, and balance reports. Payment orders remain view-only.

Permission sets: Accounts Manager, Financial Controls

ResourceActions
Balance ReportsView, Create, Edit, Delete
Bank ConnectionsView
Categorization MetadataView, Create, Edit, Delete
Internal Account GroupsView, Create, Edit, Delete
Internal AccountsView, Create, Edit, Delete
Payment Approval RulesView, Create, Edit, Delete
Payment OrdersView
Reconciliation RulesView, Create, Edit, Delete
Sweep RulesView, Create, Edit, Delete
Transaction Categorization RulesView, Create, Edit, Delete
TransactionsView, Create, Edit, Delete
User GroupsView
UsersView
Virtual AccountsView, Create, Edit, Delete

API Manage All

Unrestricted access for API keys. This role is assignable to API keys only, not to users.

Permission sets: API Manage All

Grants: all actions on all resources.