Team Management
Admins manage their organization's team β inviting members, assigning roles, and controlling access.
Inviting members
Admins invite members by email. The invitee receives a link, authenticates, and joins the organization with the role chosen at invite time. Invites expire after 7 days and can be revoked or resent. Membership is always explicit β there is no email-domain auto-join.
If the organization is already active, invited members are cleared to transact as soon as they accept.
Roles & permissions
Every member has exactly one role, and permissions derive from that role.
Admin
Full control β manage the team, run KYB, and perform all operations
Withdrawals Manager
Create deposits and submit withdrawals
Whitelisting Manager
Whitelist withdrawal addresses and create deposits
Viewer
Read-only access to portfolio, reports, and activity
Key boundaries:
Only admins invite members, change roles, suspend members, and run KYB.
Verifying (whitelisting) an address requires the Whitelisting Manager (or admin) role.
Submitting a withdrawal requires the Withdrawals Manager (or admin) role.
The two manager roles are separate: a Whitelisting Manager cannot submit withdrawals, and a Withdrawals Manager cannot verify addresses. Both can create deposits.
Member lifecycle
Admins can change a member's role or suspend a member; suspension takes effect on the member's next request and can be reversed by reactivating them. Admins can also change another admin's role β including downgrading an admin to a more restrictive role. Admins cannot suspend themselves or change their own role.
Wallet verification
Before the organization can withdraw to an external address, that address must be verified (whitelisted). A Whitelisting Manager or admin submits the address; it is screened through Tesseract's compliance checks (travel rule and wallet risk screening) and becomes available for withdrawals once approved. Until then it stays on hold. Verified addresses are shared across the organization.
Last updated
Was this helpful?
