Roles & Permissions
VaultAP uses a role-based access control (RBAC) model with three roles. Every user is assigned exactly one role, and permissions are enforced at the API level — not just in the UI.
Role Summary
| Role | Purpose |
|---|---|
| Admin | Full control over the organization: settings, users, risk configuration, and all invoice actions |
| Reviewer | Day-to-day invoice review: can view and act on invoices, view vendors and reports, but cannot change settings or manage users |
| Viewer | Read-only access for stakeholders who need visibility into dashboards, reports, and the audit trail |
Full Permissions Table
Dashboard
View dashboard overviewAdmin ✗Reviewer ✗Viewer ✗
View metric cards and chartsAdmin ✗Reviewer ✗Viewer ✗
Invoices
View invoice listAdmin ✗Reviewer ✗Viewer ✗
View invoice detailAdmin ✗Reviewer ✗Viewer ✗
Approve an invoiceAdmin ✗Reviewer ✗Viewer ✗
Reject an invoiceAdmin ✗Reviewer ✗Viewer ✗
Escalate an invoiceAdmin ✗Reviewer ✗Viewer ✗
Upload an invoice manuallyAdmin ✗Reviewer ✗Viewer ✗
Vendors
View vendor listAdmin ✗Reviewer ✗Viewer ✗
View vendor detailAdmin ✗Reviewer ✗Viewer ✗
Edit vendor informationAdmin ✗Reviewer ✗Viewer ✗
Reports
View reports and chartsAdmin ✗Reviewer ✗Viewer ✗
Export report data as CSVAdmin ✗Reviewer ✗Viewer ✗
Audit Trail
View audit trailAdmin ✗Reviewer ✗Viewer ✗
Export audit trail as CSVAdmin ✗Reviewer ✗Viewer ✗
Settings
View organization settingsAdmin ✗Reviewer ✗Viewer ✗
Modify organization settingsAdmin ✗Reviewer ✗Viewer ✗
Manage team membersAdmin ✗Reviewer ✗Viewer ✗
Modify risk configurationAdmin ✗Reviewer ✗Viewer ✗
Modify notification settingsAdmin ✗Reviewer ✗Viewer ✗
User Account
Edit own profileAdmin ✗Reviewer ✗Viewer ✗
Enable/disable own MFAAdmin ✗Reviewer ✗Viewer ✗
Manage own notification preferencesAdmin ✗Reviewer ✗Viewer ✗
Separation of Duties
In addition to role-based permissions, VaultAP enforces a separation-of-duties rule:
A Reviewer cannot approve or reject an invoice that they themselves escalated. A different Reviewer or Admin must make the final decision. This is enforced at the system level and cannot be overridden by any role.
Permission Enforcement
Permissions are enforced at the API layer, not just in the UI. Even if a user manipulates the front-end client, the server rejects any request that exceeds the user's role. All permission-denied events are recorded in the audit trail.