01Basic concepts
The role model is built around enterprise accounts, members, roles, permissions, and teams.
- Enterprise account
- Member
- Role
- Permission
- Team
02Super administrator
The super administrator has the highest management permissions for an enterprise account and should be assigned only to a small number of trusted core administrators.
- Manage enterprise account
- Add and remove members
- Set role permissions
- Enable or disable modules
- View system configuration
- Manage data scope
- View operation records
- Configure workflow rules
03Administrator
Administrators handle daily system configuration and member management. They do not always need full system permissions and can be restricted based on enterprise requirements.
- Manage member accounts
- Assign teams and roles
- Configure selected modules
- View team data
- Manage task queues
- View basic reports
04Operations staff
Operations staff handle daily customer and business process work and are often the primary users of Finger Manager.
- View client profiles
- Follow client status
- Handle operations tasks
- View tickets and notes
- Handle basic review queues
- Submit review requests
- View related reports
05Customer service staff
Customer service staff handle client communication, material follow-up, and issue processing. They do not always need access to complete trading, finance, or risk data.
- View basic client information
- Create or handle client tickets
- Follow KYC supplements
- Add client notes
- View client status
- Receive task reminders
06KYC reviewers
KYC reviewers handle customer identity materials and onboarding review workflows. Enterprises can restrict access to KYC data based on internal compliance requirements.
- View KYC materials
- Handle KYC review tasks
- Mark approved, rejected, or supplement required
- Add review notes
- View historical review records
- Submit review requests
07Payment reviewers
Payment reviewers handle deposit, withdrawal, and payment-related review workflows. They often need to collaborate with operations, customer service, and risk teams.
- View payment review queues
- Handle deposit requests
- Handle withdrawal requests
- Mark payment status
- Add review comments
- Submit exception tasks
- Export payment-related reports
08Trading operations staff
Trading operations staff support trading-related operational matters. They are not trading decision makers; their role is operational support and process handling.
- View account trading status
- Handle symbol permission requests
- Follow trading-related tasks
- Manage trading operations requests
- View account status change records
- Assist with trading exceptions
09Risk staff
Risk staff handle risk alerts, exception events, and account status monitoring. They need necessary data access but do not always need system administration permissions.
- View risk events
- Handle exception alerts
- View client risk status
- View KYC and permission-related information
- Submit restriction, review, or escalation requests
- Add risk handling records
- View risk reports
10Compliance staff
Compliance staff handle review, auditability, and internal compliance workflows. They usually need strong audit visibility but may not participate in daily task handling.
- View audit records
- View KYC status
- View permission change records
- View risk handling history
- Review exception events
- Export compliance-related records
- View operation logs
11Management
Management mainly views business overviews, team efficiency, risk status, and reports. Permissions should lean toward viewing and review rather than direct handling of every task.
- View business overview
- View team performance
- View risk overview
- View report data
- View task handling status
- View key metrics
12Permission types
Permissions define what members can view, operate, manage, or export. Export permissions should be configured carefully and assigned only when there is a clear business need.
- View permissions: pages, modules, customer data, KYC, payment records, risk events, reports, logs
- Operation permissions: approve, reject, request supplements, submit review, modify client status, create tasks, close tasks
- Management permissions: add members, delete members, modify roles, configure modules, set workflows, manage enterprise information
- Export permissions: export data or reports
13Data scope
Data scope helps enterprises maintain information security and responsibility boundaries when many people collaborate.
- Own tasks only
- Team data
- Specific department data
- Specific region data
- Specific client group data
- Enterprise-wide data
14Role configuration suggestions
Enterprises can start with simple roles and increase granularity as team size, departments, regions, and business lines grow.
- Small teams: administrator, operations staff, reviewers, management
- Medium teams: administrator, customer service, KYC reviewers, payment reviewers, risk staff, management
- Large teams: headquarters administrators, regional administrators, IB managers, customer service teams, KYC teams, payment operations, trading operations, risk teams, compliance teams, management
15Best practices
Role and permission settings should be reviewed regularly, especially after personnel changes, job changes, or team restructuring.
- Least privilege: members should only have the permissions required to complete their work
- Review permissions regularly
- Assign administrator permissions carefully
- Keep records for key operations
- Handle departures and job changes promptly
16Role model launch steps
The role model is not a one-time setup. Enterprises can adjust it as the business and internal management requirements evolve.
- Map the enterprise organization structure
- Confirm teams using Finger Manager
- Define each team's responsibilities
- Set basic roles
- Configure view and operation permissions
- Configure data scopes
- Invite members
- Test permissions
- Launch
- Review permissions regularly
17Related documentation
Role configuration should be planned together with product concepts and workflow structure so permissions match real operating responsibilities.