Standard Permission Set Reference
What each Modern Treasury standard permission set grants
Modern Treasury ships a set of standard (managed) permission sets. They cannot be edited, but they can be assigned to roles as-is or cloned as the starting point for a custom permission set.
This page lists every standard permission set and every standard role, the resources each covers, and the actions each allows, so you can tell what a set or role grants without assigning it first.
Actions use the same names as the dashboard: View, Create, Edit, Delete, plus Review (approve a payment order or external account) and Reconcile / Unreconcile (match or unmatch an expected payment).
Standard Roles at a Glance
| Standard Role | Standard Permission Sets |
|---|---|
| Administrator | Administrator |
| Engineering | Developer, API Manager |
| Finance | Payments, Invoicing, Reconciliation Operations, FX |
| Finance Manager | Accounts Manager, Financial Controls |
There is also an API Manage All role, which contains the API Manage All permission set and is assignable to API keys rather than users. The Ledgers, Ledger Viewer, and Finance Viewer permission sets are not part of any standard role and can be added to a role of your own.
Each role is broken down in Standard Roles in Detail below.
Choosing Between Similar Sets
Several resources appear in more than one standard permission set, at different access levels. The most common points of confusion:
- Payment Flows vs. Payment Orders. Payment Flows are embeddable UI flows and belong to the Developer set. Payment orders — the instruction to move money — belong to Payments and Invoicing (create, view, edit, review), and are view-only in Financial Controls and Finance Viewer.
- Expected Payments. Included in Reconciliation Operations (full access plus Reconcile and Unreconcile), Invoicing (view and create only), and Finance Viewer (view only). They are not part of the Payments set.
- Internal Accounts. View-only in Reconciliation Operations, FX, and Finance Viewer; view and edit in Payments and Invoicing; full access in Accounts Manager and Financial Controls.
- Ledger Transactions. Create, view, and edit in Payments, Invoicing, and Reconciliation Operations; full access in Ledgers; view-only in Ledger Viewer.
- Sweep Rules appear in both Payments and Financial Controls with full access.
Standard Permission Sets
Administrator
Unrestricted access to every resource and action, including user management, roles, and permission sets. This is the only set that can administer access itself.
Grants: all actions on all resources.
Developer
Build and debug an integration with Modern Treasury: embeddable flows, publishable keys, webhook endpoints, request logs, and events. This is the set that contains Payment Flows — it does not grant access to payment orders, expected payments, or accounts.
| Resource | Actions |
|---|---|
| Account Collection Flows | View, Create, Edit, Delete |
| Bulk Requests | View |
| Events | View |
| Payment Flows | View, Create, Edit, Delete |
| Publishable Keys | View, Create, Edit, Delete |
| Request Logs | View |
| User Onboarding Flows | View, Create, Edit, Delete |
| Webhook Endpoints | View, Create, Edit, Delete |
Not included: Payment orders, expected payments, internal accounts, ledgers, and users.
API Manager
Create, view, and revoke API keys, and view the roles that can be assigned to them.
| Resource | Actions |
|---|---|
| API Keys | View, Create, Edit, Delete |
| Roles | View |
Not included: Any payments, accounts, or ledger resource.
Reconciliation Operations
Reconcile expected payments against transactions, and record the ledger side of a match. This is the only standard set that grants the Reconcile and Unreconcile actions.
| Resource | Actions |
|---|---|
| Bank Connections | View |
| Counterparties | View |
| Expected Payments | View, Create, Edit, Delete, Reconcile, Unreconcile |
| Internal Accounts | View |
| Ledger Accounts | View, Create, Edit |
| Ledger Transactions | View, Create, Edit |
| Ledgers | View |
| Reconciliation Groups | View |
| Transaction Line Items | View, Create, Edit, Delete |
| Transactions | View |
Not included: Payment orders, invoices, and rules.
FX
Request and manage foreign exchange quotes.
| Resource | Actions |
|---|---|
| FX Quotes | View, Create, Edit, Delete |
| Internal Accounts | View |
Not included: Payment orders and internal account changes.
Payments
Originate and manage payments end to end, along with the counterparty and external account data payments depend on. Note that it also grants full access to counterparties, sweep rules, returns, and reversals, and that it does not grant expected payments.
| Resource | Actions |
|---|---|
| Account Details for External Accounts | View |
| Bank Connections | View |
| Counterparties | View, Create, Edit, Delete |
| External Accounts | View, Create, Edit, Delete, Review |
| File Transfers | View |
| Incoming Payment Details | View, Create, Edit, Delete |
| Internal Accounts | View, Edit |
| Ledger Accounts | View |
| Ledger Transactions | View, Create, Edit |
| Ledgers | View |
| Payment Orders | View, Create, Edit, Review |
| Returns | View, Create, Edit, Delete |
| Reversals | View, Create, Edit, Delete |
| Sweep Rules | View, Create, Edit, Delete |
Not included: Expected payments, invoices, ledgers beyond ledger transactions, rules, and users.
Invoicing
Create, send, and collect invoices, including the payment orders and expected payments generated when an invoice is paid.
| Resource | Actions |
|---|---|
| Counterparties | View |
| Expected Payments | View, Create |
| External Accounts | View |
| Internal Accounts | View, Edit |
| Invoices | View, Create, Edit, Delete |
| Ledger Account Settlements | View, Edit |
| Ledger Transactions | View, Create, Edit |
| Payment Orders | View, Create, Edit, Review |
Not included: Transactions, reconciliation actions, and rules.
Accounts Manager
Set up and maintain internal and virtual accounts and the transactions recorded against them.
| Resource | Actions |
|---|---|
| Internal Accounts | View, Create, Edit, Delete |
| Transactions | View, Create, Edit, Delete |
| Virtual Accounts | View, Create, Edit, Delete |
Not included: Payment orders, expected payments, and ledgers.
Financial Controls
Configure the controls layer: payment approval rules, reconciliation rules, transaction categorization, internal account groups, and balance reports. Payment orders are view-only in this set.
| Resource | Actions |
|---|---|
| Balance Reports | View, Create, Edit, Delete |
| Bank Connections | View |
| Categorization Metadata | View, Create, Edit, Delete |
| Internal Account Groups | View, Create, Edit, Delete |
| Internal Accounts | View, Create, Edit, Delete |
| Payment Approval Rules | View, Create, Edit, Delete |
| Payment Orders | View |
| Reconciliation Rules | View, Create, Edit, Delete |
| Sweep Rules | View, Create, Edit, Delete |
| Transaction Categorization Rules | View, Create, Edit, Delete |
| User Groups | View |
| Users | View |
Not included: Creating or approving payment orders.
Ledgers
Full read and write access to Ledgers, ledger accounts, ledger transactions, entries, categories, settlements, and statements.
| Resource | Actions |
|---|---|
| Ledger Account Categories | View, Create, Edit, Delete |
| Ledger Account Settlements | View, Create, Edit, Delete |
| Ledger Account Statements | View, Create, Edit, Delete |
| Ledger Accounts | View, Create, Edit, Delete |
| Ledger Entries | View, Create, Edit, Delete |
| Ledger Transactions | View, Create, Edit, Delete |
| Ledgers | View, Create, Edit, Delete |
Not included: Payments, accounts, counterparties, and transactions.
Finance Viewer
View-only access across payments, accounts, counterparties, and transactions. Grants no write actions.
| Resource | Actions |
|---|---|
| Account Details for External Accounts | View |
| Balance Reports | View |
| Bank Connections | View |
| Counterparties | View |
| Expected Payments | View |
| External Accounts | View |
| Internal Account Groups | View |
| Internal Accounts | View |
| Payment Orders | View |
| Returns | View |
| Reversals | View |
| Transactions | View |
| Virtual Accounts | View |
Not included: Any create, edit, or delete action, and all ledger resources.
Ledger Viewer
View-only access across Ledgers and all ledger objects. Grants no write actions.
| Resource | Actions |
|---|---|
| Ledger Account Categories | View |
| Ledger Account Settlements | View |
| Ledger Account Statements | View |
| Ledger Accounts | View |
| Ledger Entries | View |
| Ledger Event Handlers | View |
| Ledger Transactions | View |
| Ledgerable Events | View |
| Ledgers | View |
Not included: Any create, edit, or delete action.
API Manage All
Unrestricted access for API key actors — the API key equivalent of Administrator. Only assignable to API keys, not to users.
Grants: all actions on all resources.
Standard Roles in Detail
Each standard role is a bundle of standard permission sets. Where sets overlap on a resource, the role grants the union of their actions — the tables below show that combined result.
Administrator
Full access to the platform, including user management, roles, and permission sets. Assigned to the default Administrators group.
Permission sets: Administrator
Grants: all actions on all resources.
Engineering
Everything needed to build and operate an integration, plus API key management. Grants no access to payments, accounts, or ledgers.
Permission sets: Developer, API Manager
| Resource | Actions |
|---|---|
| API Keys | View, Create, Edit, Delete |
| Account Collection Flows | View, Create, Edit, Delete |
| Bulk Requests | View |
| Events | View |
| Payment Flows | View, Create, Edit, Delete |
| Publishable Keys | View, Create, Edit, Delete |
| Request Logs | View |
| Roles | View |
| User Onboarding Flows | View, Create, Edit, Delete |
| Webhook Endpoints | View, Create, Edit, Delete |
Finance
Day-to-day finance operations: originating payments, invoicing, reconciliation, and FX. Because its four sets overlap, the role's effective access on a shared resource is the broadest level any one set grants — for example Internal Accounts end up View and Edit, and Ledger Transactions end up View, Create, and Edit.
Permission sets: Payments, Invoicing, Reconciliation Operations, FX
| Resource | Actions |
|---|---|
| Account Details for External Accounts | View |
| Bank Connections | View |
| Counterparties | View, Create, Edit, Delete |
| Expected Payments | View, Create, Edit, Delete, Reconcile, Unreconcile |
| External Accounts | View, Create, Edit, Delete, Review |
| FX Quotes | View, Create, Edit, Delete |
| File Transfers | View |
| Incoming Payment Details | View, Create, Edit, Delete |
| Internal Accounts | View, Edit |
| Invoices | View, Create, Edit, Delete |
| Ledger Account Settlements | View, Edit |
| Ledger Accounts | View, Create, Edit |
| Ledger Transactions | View, Create, Edit |
| Ledgers | View |
| Payment Orders | View, Create, Edit, Review |
| Reconciliation Groups | View |
| Returns | View, Create, Edit, Delete |
| Reversals | View, Create, Edit, Delete |
| Sweep Rules | View, Create, Edit, Delete |
| Transaction Line Items | View, Create, Edit, Delete |
| Transactions | View |
Finance Manager
Account setup and the controls layer: internal and virtual accounts, transactions, approval and reconciliation rules, categorization, and balance reports. Payment orders remain view-only.
Permission sets: Accounts Manager, Financial Controls
| Resource | Actions |
|---|---|
| Balance Reports | View, Create, Edit, Delete |
| Bank Connections | View |
| Categorization Metadata | View, Create, Edit, Delete |
| Internal Account Groups | View, Create, Edit, Delete |
| Internal Accounts | View, Create, Edit, Delete |
| Payment Approval Rules | View, Create, Edit, Delete |
| Payment Orders | View |
| Reconciliation Rules | View, Create, Edit, Delete |
| Sweep Rules | View, Create, Edit, Delete |
| Transaction Categorization Rules | View, Create, Edit, Delete |
| Transactions | View, Create, Edit, Delete |
| User Groups | View |
| Users | View |
| Virtual Accounts | View, Create, Edit, Delete |
API Manage All
Unrestricted access for API keys. This role is assignable to API keys only, not to users.
Permission sets: API Manage All
Grants: all actions on all resources.
Updated 15 days ago