This article lists every capability in BNDRY and which roles can use it from the app's user interface. A role is either composable (Reader, Writer, Admin, Collaborator build on shared read/write groups) or standalone (View Only Admin, HR, Investigations and Duty Manager each have their own self-contained permission set, not inherited from Reader or Writer).
How to read this table
✅ — full access
👁 — view only
✏️ — limited access (restricted to a narrower scope, such as records the role's own account created)
❌ — not available to this role
Permissions matrix
| Capability | Admin | Writer | Reader | View Only Admin | HR | Investigations | Duty Manager | Collaborator | Notes |
|---|---|---|---|---|---|---|---|---|---|
| Sign in to the app | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | Collaborator only gets the forms/customer portal, not the staff app. |
| Entities — view detail pages | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | ❌ | ❌ | Duty Manager can't open an entity's detail page. |
| Entities — list / browse | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | ✏️ | ❌ | Duty Manager only sees entities through the workspace-creation picker, not a standalone Entities page. |
| Entities — view relationships | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | ❌ | Duty Manager sees relationships on the workspace page, not the entity detail page. |
| Entities — create / update | ✅ | ✅ | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | |
| Entities — archive | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | The archive option shows in the menu for every role, but only Admin and Writer can actually archive. |
| Entities — add / remove tags | ✅ | ✅ | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | |
| Entities — add files / attachments | ✅ | ✅ | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | |
| Entities — view evaluation input | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | ❌ | ❌ | |
| Activity logs — view | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | ❌ | ❌ | |
| Activity logs — create | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ❌ | ❌ | |
| Activity logs — update / archive | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | |
| Activity log type creation | ✏️ | ✏️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | Not a dedicated admin screen — typing a new type name while filling in a custom activity log creates it. Editing an existing type isn't available to any role. |
| Workspaces — view | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | Collaborator sees only the single workspace they were invited into, via the customer portal, not the staff app. |
| Workspaces — create / update / change state | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ✅ | ❌ | |
| Workspaces — archive | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | The archive option shows in the menu for every role, but only Admin and Writer can actually archive. Unarchive doesn't work for anyone. |
| Workspaces — generate magic link | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ✅ | ❌ | |
| Forms — view templates | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | ❌ | ❌ | |
| Forms — fill in / submit / update | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ✅ | ✏️ | Collaborator is limited to the forms attached to their own workspace. |
| Form templates — create / edit / clone / archive | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | Only Admin can create, edit, clone or archive a form template. |
| Files — view / download | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | Duty Manager sees files on the workspace page, not the entity page. |
| Files — upload | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ✅ | ✏️ | Collaborator is limited to their own workspace. |
| Notes — view | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | |
| Notes — create | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ✅ | ✏️ | Collaborator is limited to their own workspace. |
| Notes — update / archive | ✏️ | ✏️ | ❌ | ❌ | ✏️ | ✏️ | ❌ | ✏️ | Limited to notes the role's own account created — archiving someone else's note is rejected. |
| Documents — view | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | ❌ | ❌ | |
| Documents — create | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | |
| Tags — view tag types & definitions | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | ❌ | ❌ | |
| Job: Onboard Individual — run | ✅ | ✅ | ❌ | ❌ | ❌ | ✅ | ❌ | ❌ | Started from a workspace form, not the entity page. |
| Job: Verify Individual — read & run | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ❌ | ❌ | |
| Job: PEP / Sanctions — read & run | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ❌ | ❌ | |
| Job: ID Verify — read & run | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ❌ | ❌ | |
| Job: KYB Profile Generation — read & run | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ❌ | ❌ | |
| Tenant settings — view (UI / risk levels / custom fields) | 👁 | ❌ | ❌ | 👁 | ❌ | ❌ | ❌ | ❌ | |
| Tenant settings — edit (UI, custom fields) | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | |
| Integrations — view | 👁 | ❌ | ❌ | 👁 | ❌ | ❌ | ❌ | ❌ | |
| ConnectID (start auth, retrieve tokens) | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | |
| Truuth (create verification session) | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | |
| Alerts / Inbox — view | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | 👁 | ❌ | |
| SMR / UAR filing | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ❌ | ❌ | Lives inside Activity Logs. |
| Entity relationship creation | ✅ | ✅ | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ |
Key behavioural notes
- Duty Manager can't open an entity's detail page directly. They can still pick an entity when starting a workspace, and see relationships from the workspace page.
- HR can create and update entity records, but can't archive them (that's Admin/Writer only, despite the menu option showing for everyone). HR can't edit tenant settings.
- Investigations can run every screening job, including Onboard Individual, but can't create or edit entity records, or tag them, directly.
- View Only Admin is the most powerful read-only role: the only role besides Admin that can see tenant settings and integrations (read-only).
- Admin is the only role that can change tenant configuration: settings, custom fields, and form templates.
- Collaborator is scoped to a single shared workspace via the customer portal, not the staff app. No access to entities, activity logs, jobs, or tenant settings.
Comments
0 comments
Article is closed for comments.