VaultAP Docs

Roles & Permissions

VaultAP uses a role-based access control (RBAC) model with three roles. Every user is assigned exactly one role, and permissions are enforced at the API level — not just in the UI.

Role Summary

RolePurpose
AdminFull control over the organization: settings, users, risk configuration, and all invoice actions
ReviewerDay-to-day invoice review: can view and act on invoices, view vendors and reports, but cannot change settings or manage users
ViewerRead-only access for stakeholders who need visibility into dashboards, reports, and the audit trail

Full Permissions Table

Dashboard

View dashboard overviewAdmin ✗Reviewer ✗Viewer ✗
View metric cards and chartsAdmin ✗Reviewer ✗Viewer ✗

Invoices

View invoice listAdmin ✗Reviewer ✗Viewer ✗
View invoice detailAdmin ✗Reviewer ✗Viewer ✗
Approve an invoiceAdmin ✗Reviewer ✗Viewer ✗
Reject an invoiceAdmin ✗Reviewer ✗Viewer ✗
Escalate an invoiceAdmin ✗Reviewer ✗Viewer ✗
Upload an invoice manuallyAdmin ✗Reviewer ✗Viewer ✗

Vendors

View vendor listAdmin ✗Reviewer ✗Viewer ✗
View vendor detailAdmin ✗Reviewer ✗Viewer ✗
Edit vendor informationAdmin ✗Reviewer ✗Viewer ✗

Reports

View reports and chartsAdmin ✗Reviewer ✗Viewer ✗
Export report data as CSVAdmin ✗Reviewer ✗Viewer ✗

Audit Trail

View audit trailAdmin ✗Reviewer ✗Viewer ✗
Export audit trail as CSVAdmin ✗Reviewer ✗Viewer ✗

Settings

View organization settingsAdmin ✗Reviewer ✗Viewer ✗
Modify organization settingsAdmin ✗Reviewer ✗Viewer ✗
Manage team membersAdmin ✗Reviewer ✗Viewer ✗
Modify risk configurationAdmin ✗Reviewer ✗Viewer ✗
Modify notification settingsAdmin ✗Reviewer ✗Viewer ✗

User Account

Edit own profileAdmin ✗Reviewer ✗Viewer ✗
Enable/disable own MFAAdmin ✗Reviewer ✗Viewer ✗
Manage own notification preferencesAdmin ✗Reviewer ✗Viewer ✗

Separation of Duties

In addition to role-based permissions, VaultAP enforces a separation-of-duties rule:

A Reviewer cannot approve or reject an invoice that they themselves escalated. A different Reviewer or Admin must make the final decision. This is enforced at the system level and cannot be overridden by any role.

Permission Enforcement

Permissions are enforced at the API layer, not just in the UI. Even if a user manipulates the front-end client, the server rejects any request that exceeds the user's role. All permission-denied events are recorded in the audit trail.