Understanding Roles
Overview
All Dex users must be assigned to at least one role. Dex uses Roles-Based Access Control (RBAC) protocols to define user roles. Roles are sets of individual permissions for a user and are tied to the organization(s) to which the user belongs. A user can have more than one role and hence, more than one set of permissions. Permissions control what a user can access and what tasks he or she can perform.
Merchant Roles
| Resource | Permission | Merchant Admin | Merchant Manager | Merchant User | Developer | View Only |
|---|
| Addresses | Create | a | a | a | ||
| Delete | a | a | a | |||
| Read | a | a | a | a | a | |
| Update | a | a | a | |||
| API Keys | Create | a | a | |||
| Delete | a | a | ||||
| Read | a | a | ||||
| Update | a | a | ||||
| Customers | Create | a | a | a | ||
| Read | a | a | a | a | a | |
| Update | a | a | a | |||
| Disputes‡ | Read | a | a | a | ||
| Update | a | |||||
| Documents | Create | a | ||||
| Delete | a | |||||
| Read | a | a | a | a | a | |
| Update | a | |||||
| Funding Entries | Read | a | a | a | a | |
| Invitations | Create | a | ||||
| Delete | a | |||||
| Read | a | a | a | a | a | |
| Update | a | a | ||||
| IP Whitelist | Read | a | ||||
| Update | a | |||||
| Locations | Read | a | a | a | a | a |
| Payment Methods | Create | a | a | a | ||
| Delete | a | a | a | |||
| Read | a | a | a | a | a | |
| Update | a | a | a | |||
| PayPal | Read | a | ||||
| Update | ||||||
| Roles | Read | a | a | |||
| Settlements | Read | a | a | a | a | a |
| Transactions | Auth | a | a | a | ||
| Capture | a | a | a | |||
| Disburse* | a | |||||
| Force | a | a | ||||
| Read | a | a | a | a | a | |
| Resubmit | a | a | ||||
| Sale | a | a | a | |||
| Verify | a | a | a | |||
| Void | a | a | a | |||
| Users | Delete | a | ||||
| Invite | a | |||||
| Read | a | a | a | a | a | |
| Update | a | a |
*Only Merchant Admin users can perform disburse/credit transactions. To assign this permission to a Merchant Manager or Merchant User, the Admin must assign users to the Create Credit role.
‡Merchant Admins can assign other users to the Dispute Manager role, which will enable them to view and update disputes.
The permissions inherent in these roles cannot be modified.
Partner Roles
Dex comes with the following generic, predefined roles and permissions for partners:
| Resource | Permission | ISO - No Support | ISV - No Support | ISV - Support | Developer | View Only | Partner Admin |
|---|
| Addresses | Create | a | |||||
| Delete | a | ||||||
| Read | a | a | a | a | a | a | |
| Update | a | ||||||
| API Keys | Create | a | a | a | |||
| Delete | a | a | a | ||||
| Read | a | a | a | a | a | ||
| Update | a | a | a | ||||
| Applications | Read | a | a | a | a | a | |
| Update | a | a | a | a | a | ||
| Customers | Create | a | |||||
| Delete | a | ||||||
| Export | a | ||||||
| Import | a | ||||||
| Read | a | a | a | a | a | a | |
| Update | a | ||||||
| Dashboard | Read | a | a | a | a | a | |
| Disputes | Read | a | a | a | a | a | |
| Update | a | a | a | ||||
| Documents | Create | a | a | a | |||
| Read | a | a | a | a | |||
| Update | a | a | a | ||||
| Delete | a | a | a | ||||
| Funding Entries | Read | a | a | a | a | a | a |
| Invitations | Create | a | a | a | a | ||
| Delete | a | a | a | a | |||
| Read | a | a | a | a | |||
| Update | a | a | a | a | |||
| IP Allow List | Read | a | a | a | a | ||
| Update | a | a | a | a | |||
| Locations | Read | a | a | a | a | a | a |
| Create | a | ||||||
| Merchant Defined Fields | Create | ||||||
| Delete | |||||||
| Read | a | a | a | a | a | a | |
| Update | |||||||
| MSA | Read | a | |||||
| Organization | Create | a | a | ||||
| Read | a | a | a | a | a | a | |
| Update | a | a | a | a | |||
| Payment Methods | Create | a | |||||
| Delete | a | ||||||
| Read | a | a | a | a | a | ||
| Update | a | ||||||
| PayPal | Read | a | a | a | a | ||
| Update | a | ||||||
| Reports | Read | a | a | a | a | ||
| Roles | Read | a | a | a | |||
| Schedules | Create | a | |||||
| Delete | a | ||||||
| Read | a | a | a | a | a | a | |
| Update | a | ||||||
| Settlements | Read | a | a | a | a | a | |
| Transactions | Auth | a | |||||
| Capture | a | ||||||
| Force | a | ||||||
| Read | a | a | a | a | a | ||
| Resubmit | a | ||||||
| Reverse | a | ||||||
| Sale | a | ||||||
| Verify | a | ||||||
| Void | a | ||||||
| Users | Delete | a | a | a | |||
| Invite | a | a | a | ||||
| Read | a | a | a | ||||
| Update | a | a | a | ||||
| Webhook | Create | a | |||||
| Delete | a | ||||||
| Read | a | a | a | ||||
| Update | a |
The Invite permission enables you to invite users to Dex with the same or fewer permissions. You cannot invite a user to a role with more permissions than your own role.
The permissions inherent in these roles cannot be modified.
Enterprise Roles
Dex comes with the following generic, predefined roles and permissions for Enterprise users:
| Resource | Permission | Enterprise Admin | Enterprise Manager | Enterprise User | Enterprise View Only |
|---|
| Addresses | Create | a | a | a | |
| Delete | a | a | a | ||
| Read | a | a | a | a | |
| Update | a | a | a | ||
| API Keys | Create | a | |||
| Delete | a | ||||
| Read | a | ||||
| Update | a | ||||
| Customers | Create | a | a | a | |
| Delete | a | a | a | ||
| Export | a | a | a | ||
| Read | a | a | a | a | |
| Update | a | a | a | ||
| Disputes‡ | Read | a | |||
| Update | a | ||||
| Documents | Read | a | a | a | a |
| Funding Entries | Read | a | a | a | |
| Invitations | Create | a | |||
| Delete | a | ||||
| Read | a | a | |||
| Update | a | a | |||
| IP Whitelist | Read | a | |||
| Update | a | ||||
| Locations | Read | a | a | a | a |
| Payment Methods | Create | a | a | a | |
| Delete | a | a | a | ||
| Read | a | a | a | a | |
| Update | a | a | a | ||
| Roles | Read | a | a | ||
| Schedules | Create | a | a | a | |
| Delete | a | a | a | ||
| Read | a | a | a | a | |
| Update | a | a | a | ||
| Settlements | Read | a | a | a | a |
| Transactions | Auth | a | a | a | |
| Capture | a | a | a | ||
| Create | a | a | a | ||
| Disburse | a | ||||
| Force | a | a | |||
| Read | a | a | a | a | |
| Resubmit | a | a | |||
| Reverse | a | a | a | ||
| Sale | a | a | a | ||
| Verify | a | a | a | ||
| Void | a | a | a | ||
| Users | Delete | a | a | a | |
| Read | a | a | a | ||
| Update | a | a | a |
*Only Enterprise Admin users can perform disburse/credit transactions. To assign this permission to a Enterprise Manager or Enterprise User, the Admin must assign users to the Create Credit role.
‡Enterprise Admins can assign other users to the Dispute Manager role, which will enable them to view and update disputes.
The Invite permission enables you to invite users to Dex with the same or fewer permissions. You cannot invite a user to a role with more permissions than your own role.
The permissions inherent in these roles cannot be modified.
Creating Customized Roles
NOTE: You cannot create a role that has more permissions than your own assigned role.
To create a customized role for a user with specific permissions, complete the following steps:
- Navigate to the Users Datagrid by clicking Manage > Users in the Dex menu.
- Click the Manage Roles button. The Manage Roles Screen displays.
- Click the Create New Role button. The Create New Role Modal displays. Remember, you will only see the permissions currently assigned to your user account.
- Enter a unique name for the custom role in the Role field.
- Scroll through the list of available permissions and click the checkbox(es) next to the permission(s) you want to add to this role. You can also search for a desired permission by using the Search free-text field above the list of permissions.
- After selecting the desired permissions, click the Create New Role button on the Create New Role Modal. Dex returns you to the Manage Roles Screen with the custom role displayed in the list of available roles.
Editing Customized Roles
NOTE: Pre-defined roles provided by Forte cannot be edited or deleted.
To edit a customized role, complete the following steps:
- Navigate to the Users Datagrid by clicking Manage > Users in the Dex menu.
- Click the Manage Roles button. The Manage Roles Screen displays.
- Hover over the name of the role you wish to edit. A pop-out menu displays.
- Click the Edit button. The View/Edit Permissions Modal displays.
- To change the name of the role, click the Edit button next to the role's name. A free-text field displays. Enter the new name of the role and click Save. If you want to edit the permissions of this role, continue to the next step. If you've completed your edits, click the Save button at the bottom of the View/Edit Permissions Modal.
- Scroll through the list of available permissions and update the given permissions for this role by clicking the checkbox(es) next to the permission(s) you want to add or delete. You can also search for a desired permission by using the Search free-text field above the list of permissions. NOTE: You cannot create a role that has more permissions than your own assigned role.
- After updating the permissions for this role, click the Save button on the View/Edit Permissions Modal. Dex returns you to the Manage Roles Screen and displays a message indicating whether or not the update was successful.
Deleting a Customized Role
NOTE: Pre-defined roles provided by Forte cannot be edited or deleted.
To delete a customized role, complete the following steps:
- Navigate to the Users Datagrid by clicking Manage > Users in the Dex menu.
- Click the Manage Roles button. The Manage Roles Screen displays.
- Hover over the name of the role you wish to edit. A pop-out menu displays.
- Click the Delete button. The Delete Role Message displays.
- Click the OK button on the Delete Role Message to permanently delete the role.
Assigning Users to a Role
To add one or more users to a role, complete the following steps:
- Click Manage > Users in the Dex menu to access the Users Datagrid. To find the specific user, type his or her Name or Username (e.g., email) into the Search field. You can also use the Status filter to narrow down the list of users according to Active status within a specified date range.
- Click the row on which the desired user's record displays. Dex displays the User's Details Screen.
- Click the Add to Role button displayed in the "Roles" section. The Add User to Role Modal displays.
- Click the checkboxes next to the role(s) you want to give the user. NOTE: You cannot assign a user to a role with more permissions than your own role.
- Click the Add to Role button. Dex returns you to the User's Details Screen with the new role(s) listed in the "Roles" section.