Controlled feature access across Payvala, Financial Institution, Organization, and end-user operations.
The Payvala platform follows a Role-Based Access Control (RBAC) model to ensure secure and controlled access to system functionalities across FI, Organization, and User levels.
| Level | Role Type | Description |
|---|---|---|
| Financial Institution Level | Financial Institution (Admin) | Manages Financial Institution configuration and integration. |
| Organization Level | Organization (Admin) | Manages merchants, users, and settings. |
| User Level | End Users (Care User) | Performs operational activities with limited access. |
The user selects one or more permitted roles from the modal based on organization and operational scope.
Save applies the selected role mapping and returns to the user-management view with the new access profile in place.
Cancel closes the role modal and returns to the previous screen without changing the user’s current authorization set.
All role-based actions are logged to support monitoring, compliance, and investigation of privileged operations.
| FI Responsibility | Payvala Responsibility |
|---|---|
| Assign roles based on least privilege and segregation of duties. | Enforce RBAC across UI and APIs. |
| Review audit logs for sensitive operations and anomalous access. | Maintain audit trails and provide access via POEMS. |