Roles and Permissions
Roles define a user’s level of responsibility. Permissions control the data and Portal features that user can access.
How to Manage User Roles and Persmissions
This guide defines how to manage roles and permissions of a TabaPay Portal user created by a Portal admin.
Before You Begin
Ensure you are an admin or manager to edit permissions of a user.
Learn how to Create and Edit Users from the portal guide.
Roles
| Role | Who this role is for | Description |
|---|---|---|
| Admin | The primary account owner who needs access to all permissions in portal, including viewing PII and masked data. | Have full access to TabaPay Portal by default. Can create and manage other Admins, Manager, and Users. An organization must always have at least one active Admin. |
| Manager | A trusted team lead or operations manager who needs to delegate access and help manage users without controlling the organization’s highest-level administration. | Have all user-management permissions enabled by default. Can create and mange Users only. |
| User | An employee or team member who needs access to specific Portal data or features to perform their job. | Receives the specific data and feature permissions assigned by an Admin or authorized Manager. |
How Access Works
Each user has an assigned role: Admin, Manager, or User. The role determines which permissions are granted automatically, which permissions must be assigned, and which permissions are unavailable.
- Enabled by default: Granted automatically when the role is assigned.
- By assignment: Not granted automatically. An Admin or authorized Manager must explicitly assign the permission.
- Not available: Cannot be assigned to that role.
When a user’s role changes, the Portal recalculates their permissions based on the new role.
| Permission category | Permission | Admin | Manager | User |
|---|---|---|---|---|
| Data | View PII Data | Enabled by default | By assignment | By assignment |
| Data | View Unmasked Data | Enabled by default | By assignment | By assignment |
| Data | View Custom API Fields | Enabled by default, if applicable to the client | By assignment | By assignment |
| Insights Hub | View Dashboard | By assignment | By assignment | By assignment |
| Overview Dashboard | View Transaction Summary | Enabled by default | By assignment | By assignment |
| Report Builder | Access Report Builder | Enabled by default | By assignment | By assignment |
| Report Builder | Export Reports | Enabled by default | By assignment | By assignment |
| Transactions | View Real-Time Transactions | Enabled by default | By assignment | By assignment |
| Transactions | View Detailed Transactions | Enabled by default | By assignment | By assignment |
| Transactions | Void/Reverse/Refund/Delete Transactions | Enabled by default | By assignment | By assignment |
| Transactions | View Chargebacks | Enabled by default | By assignment | By assignment |
| Transactions | Manage Chargebacks | Enabled by default | By assignment | By assignment |
| Transactions | View Adjustments | Enabled by default | By assignment | By assignment |
| Transactions | View AVS | Enabled by default | By assignment | By assignment |
| Payments | Create Payment Requests | Enabled by default, if applicable to the client | By assignment | By assignment |
| Balances | View CRB Account Balances and Details | Enabled by default, if applicable to the client | By assignment | By assignment |
| Balances | View CRB Account Number | Enabled by default, if applicable to the client | By assignment | By assignment |
| Reporting | View Reports | Enabled by default | By assignment | By assignment |
| Invoices | View Invoices | Enabled by default | By assignment | By assignment |
| User Management | Create Users | Enabled by default | Enabled by default | Not available |
| User Management | Edit Users | Enabled by default | Enabled by default | Not available |
| User Management | Deactivate Users | Enabled by default | Enabled by default | Not available |
| User Management | Export User List | Enabled by default | Enabled by default | Not available |
| User Management | View User Activity | Enabled by default | Enabled by default | Not available |
| User Management | Manage Subclient Users | Enabled by default | Enabled by default when available | Not available |
Assign Permissions
- Log in to the TabaPay Portal
- On the left panel under My Organization, select Users.
- To find the user with permissions you want to view, use the search or filter features as shown in Manage Users.
- On the right side of the user row, select Actions
- Select Edit User.
- Scroll down to view the Permissions section.
- Check or unchek any boxes under Permissions.
- Review the changes.
- Select Save Changes.
Permission Reference
The Portal shows only permissions applicable to the selected organization and user. Some permissions are available only when your organization is configured for the related feature. Admins and authorized Managers can assign permissions to eligible users.
| Category | Permission | Description |
|---|---|---|
| Data | View PII Data | Allows the user to view supported personally identifiable information, such as names, addresses, phone numbers, and account details. |
| Data | View Unmasked Data | Allows the user to view full values for supported fields that are masked by default. |
| Data | View Custom API Fields | Allows the user to view custom fields sent through the Create Transaction API, when configured for the organization. |
| Insights Hub | View Dashboard | Allows the user to view the Insights Hub dashboard when the feature and seat access are enabled. |
| Overview Dashboard | View Transaction Summary | Allows the user to view transaction summaries, including counts, amounts, and limits for Pull and Push transactions. |
| Report Builder | Access Report Builder | Allows the user to access Report Builder. |
| Report Builder | Export Reports | Allows the user to export reports. |
| Transactions | View Real-Time Transactions | Allows the user to view real-time transaction data. |
| Transactions | View Detailed Transactions | Allows the user to view detailed transaction information. |
| Transactions | Search Transactions | Allows the user to search and filter transaction data. |
| Transactions | Void/Reverse/Refund/Delete Transactions | Allows the user to perform eligible transaction actions, subject to applicable business rules. |
| Transactions | View Chargebacks | Allows the user to view the Chargebacks table. |
| Transactions | Search and Filter Chargebacks | Allows the user to search and filter chargeback records. |
| Transactions | Manage Chargebacks | Allows the user to manage eligible chargeback actions. |
| Transactions | View Adjustments | Allows the user to view the Adjustments table. |
| Transactions | Search and Filter Adjustments | Allows the user to search and filter adjustment records. |
| Transactions | View AVS | Allows the user to view the AVS table. |
| Transactions | Search and Filter AVS | Allows the user to search and filter AVS records. |
| Payments | Create Pull/Push Transaction | Allows the user to create Pull or Push transactions, when enabled for the organization. |
| Payments | Create Payment Request | Allows the user to create payment request links, when enabled for the organization. |
| Balances | View CRB Account Balances and Details | Allows the user to view CRB account balances and details, when the organization has an eligible subledger account. |
| Balances | View CRB Account Number | Allows the user to view the full CRB account number, when the organization has an eligible subledger account. |
| Reports | View Reports | Allows the user to view and download reports. |
| Invoices | View Invoices | Allows the user to view and download invoices when invoice access is enabled for the organization. |
| User Management | Create Users | Allows the user to invite and create eligible users in the Portal. |
| User Management | Edit Users | Allows the user to edit eligible users’ profile details and permissions. |
| User Management | Deactivate Users | Allows the user to deactivate eligible users and remove their Portal access. |
| User Management | Export User List | Allows the user to export the user list from the Users page. |
| User Management | View User Activity | Allows the user to view the Activity Log in a user’s details panel. |
| User Management | Manage Subclient Users | Allows an eligible user to access and manage users at the subclient level when applicable. |
The permission available to a user depends on the user’s role, assigned permissions, organization type, and feature configuration. Having a permission listed in this table does not by itself enable a feature for your organization.
Permission Assignment Rules
- Admins can assign feature and data permissions to other Managers and Users.
- Managers can assign permissions to Users only.
- Managers do not automatically receive access to every new feature. An Admin or authorized Manager must assign additional access to them.
Least-Privilege Guidance
Assign only the data and features a user needs to perform their job. Review permissions regularly, especially after a user changes teams or responsibilities.
Updated about 4 hours ago
