Finverity Users: Access & Permissions Procedure

1. Purpose

This Guide defines Finverity user access requirements across UAT, migration, and Production to ensure:

  • Pre-approved and auditable access rights

  • Clear segregation of duties

  • Bank control over vendor access

  • Secure support during testing and migration

Finverity, as the SCF platform vendor, supports the client during UAT and migration. Access levels are structured as:

UAT & SIT: Read + edit rights to enable testing and issue resolution
Post Go-Live: Read-only rights for a restricted support group

This model ensures operational support without compromising client governance.

2. Responsibility & Security Ownership

Once credentials are issued for UAT and Production environments, the client is responsible for:

  • Service account lifecycle management

  • Credential storage and rotation

  • Compliance with internal security policies

3. Finverity Accounts

The service accounts listed below are automatically created in each environment.

While CS Support accounts are provided as recommendations only, it is strongly advised to keep the support team enabled across your environments throughout the various phases of implementation.

The billing account must be maintained to allow Finverity to calculate applicable fees and generate the end-of-month invoice.

The postings module service account is required for API integrations to function correctly, including the retrieval of funded instruments, generation of GL entries, and automated repayment processing.

Name

Email

Role

Finverity Support

support@finverity.com

Customer Success/Support

Billing

billing@finverity.com

Billing service account

Postings

postings@finverity.com

API-only postings service account

4. Service Account Permissions

4.1 Postings Service Account

Purpose

Supports postings module to:

  • Fetch funded instruments

  • Generate GL entries

  • Automatically close repayments

Minimum access rights for any stage
(View rights + Repayment edit rights)

Permissions

  • View companies

  • View company users

  • View company bank accounts

  • View floating rates

  • View order form templates

  • View product groups

  • View product structures

  • View programmes

  • View deals

  • View Repayments

  • View Disbursement Files

  • View Seld Onboarding

  • View Audit Trail

  • Initiate Repayments

  • Reconcile Repayments

  • Cancel Repayments

  • Manage API Keys

  • Manage Integrations

4.2 Billing Service Account

Minimum rights for any stage — View only

Purpose

Used by Finverity accounting to track billing.

Permissions

  • View companies

  • View company users

  • View company bank accounts

  • View floating rates

  • View order form templates

  • View product groups

  • View product structures

  • View programmes

  • View deals

  • View Repayments

  • View Disbursement Files

  • View Seld Onboarding

  • View Audit Trail

5. Finverity Support Access

5.1 UAT Environment Access Level - UAT period

Superadmin rights to support testing

Company & User Management

  • Create and edit companies

  • View companies

  • Manage company users

  • View company users

  • Create and edit bank accounts

  • Activate and deactivate bank accounts

  • Delete bank accounts

  • View company bank accounts

  • Approve company KYC

  • Activate companies

  • Deactivate companies

  • Reject companies

  • Submit companies for review

  • Archive companies

Rates & Templates

  • View floating rates

  • Create and edit floating rates

  • Delete floating rates

  • View fx rates

  • Create and edit fx rates

  • Delete fx rates

  • View order form templates

  • Manage order form templates

  • Upload order form templates

Products & Programmes

  • View product groups

  • Create and edit product groups

  • Delete product groups

  • View product structures

  • Create and edit product structures

  • Delete product structures

  • View programmes

  • Create and edit programmes

  • Delete programmes

Deals & Instruments

  • Create and edit deals

  • Activate and deactivate deal counterparties

  • View deals

  • Activate deals (Maker)

  • Activate deals (Checker)

  • Deactivate deals

  • Delete deals

  • Archive deals

  • Upload and Submit Instruments (Admin)

  • View uploaded instruments (Admin)

  • Fund Instruments (Admin)

Disbursements & Repayments

  • Confirm & Cancel disbursements (Admin)

  • View Disbursement Files (Admin)

  • View Repayments (Admin)

  • Initiate Repayments (Admin)

  • Cancel Repayments (Admin)

  • Reconcile Repayments (Admin)

Workflow & Security

  • Manage instrument approval workflow settings (Admin)

  • Manage My Company Users (Admin)

  • Manage My Company-level Security Settings (Admin)

  • Manage Company Notification Settings (Admin)

  • Customise Notifications

  • Approve & Reject Instruments - Funder Approval (Maker)

  • Approve & Reject Instruments - Funder Approval (Checker)

  • Manage Rejected Instruments - Funder Approval

  • Manage API Keys

  • Manage Self Onboarding

  • View Self Onboarding

  • View Audit Trail (Admin)

  • Manage Company Onboarding Comments

  • Manage Onboarding Form and Rules

  • Manage Company Sso Settings

  • Manage Bank Holidays

  • Manage Credit Note Rules

  • Manage Integrations

  • Manage Service Accounts

5.2 UAT Environment Access Level - post UAT period

After go-live, CS Support rights may be:

Option A — Restricted:
View-only rights

Option B — Retained:
Maintain UAT rights for continued testing and support

Final decision rests with the client.

5.3 Production Environment Access Level - During Client Training / Onboarding

View-Only Permissions

  • View companies

  • View company users

  • View company bank accounts

  • View floating rates

  • View order form templates

  • View product groups

  • View product structures

  • View programmes

  • View deals

  • View Repayments

  • View Disbursement Files

  • View Seld Onboarding

  • View Audit Trail

5.4 Production Environment Access Level - AfterTraining / Onboarding

Once training is complete, credentials may be:

  • Maintained for ongoing support, or

  • Revoked per client security policy