Permission reference

SQRL has 11 named permissions. All permissions are workspace-scoped unless otherwise noted. Roles are built by combining these permissions. See Roles and permissions.

Updated 05 Aug 20261 min read
PermissionControlsTypical use
OwnerFull access; bypasses all permission checksOrganisation-level administration. Cannot be assigned manually.
Manage WorkspaceWorkspace configuration, vault management, token deployment, and contract operationsAdministrators managing workspace-level operations
Manage UsersAdd, edit, and deactivate users in the workspaceUser management
Manage RolesCreate, edit, and delete rolesRole administration
Manage PermissionsAssign permissions to rolesPermission configuration
Initiate PaymentCreate and submit movementsMovement initiators
Approve PaymentSign pending movements and deploymentsAuthorised signers
View BalancesView vault and token balancesAll operational roles
View LogsAccess the activity and audit log and export log dataAuditors and compliance staff
Create WorkspaceCreate new workspaces within the organisationOrganisation-level administration
Delete WorkspaceDelete a workspaceOrganisation-level administration
info:

Only the Owner permission is fixed. Every other permission can be combined into roles of your own design. The standard roles (Admin, Approver, Initiator, Auditor) are suggested starting points, not fixed system roles.

Was this page helpful?