Access Control

One Command Center.
Control Everywhere.

Manage who can see which apps, what they can do inside them, and how money gets spent. Works for everyone, from admins to AI agents.

Access Control dashboard showing role management with granular permissions for admins, members, and agents

Granular Control Without Complexity

Per-App Permissions

Each app has its own permission surface. Grant access to Bill Pay without exposing Assets. Scope down to exactly what each role needs.

Groups

Organize users and agents into groups. Apply permissions once, inherit everywhere. Update the group, update everyone in it.

Audit Log

Every permission change, every access grant, every role assignment is logged. Know who has access to what, and who changed it.

Invite Flow

Add new team members, service providers, or agents with a role already assigned. They land with exactly the right access.

Revoke Instantly

Remove access in one click. When a contractor finishes or an agent is decommissioned, permissions disappear immediately.

Roles & Groups

Universal Roles. Custom Groups.

Start with built-in roles: Admin, Member, Service Provider. Then create custom roles and groups that match your organization's structure. Nest permissions, scope by entity, and adjust as your team evolves.

  • Admins: full platform access, user management, org configuration
  • Members: day-to-day operations, scoped to relevant apps and data
  • Service Providers: external partners with limited, auditable access
  • Custom Roles: define your own with any combination of permissions
Admin
All Apps All Actions Unlimited
Finance
Assets Bill Pay $50k limit
Accountant
Reports No Payments Read Only
AI Agent
Invoices Draft Only $1k limit
Agent-Ready

Ready for the Age of Agents

Soon, financial agents will tackle everything from drafting invoices to processing payments. Manage them as easily as you manage your team.

  • Scoped visibility: agents see only the apps and data they need
  • Action limits: draft but not approve, create but not delete
  • Spending caps: hard limits per agent, no escalation, no surprises
Coming Soon
Visibility
Control which apps and data an agent can see
AssetsBill PayInvoicesReportsContactsExchange
Actions
Control what an agent can do inside each app
ViewDraftInitiateApproveEditDelete
Spending
Set hard limits on what an agent can move
Per-Transaction: $1,000Daily: $5,000Monthly: $25,000

Three Dimensions of Control

1

Visibility

Control which apps and data are visible. A contractor doesn't need to see your treasury. Show only what's relevant.

2

Actions

Control what each role can do: initiate, approve, edit, or view-only. Each action is explicitly granted.

3

Roles

Assign permissions by role: Admin, Member, Service Provider, or custom. Update a role, update everyone in it.

Included on every plan. Transactions cost 0.5% on Pay as you go and 0.0% on flat-fee plans.

See pricing

Ready to futurize financial operations?

Get started with Mezzanine and manage organizational access in minutes.