Merchant Team & Access Management
Read-only merchant team and access visibility for organization structure, roles, departments, MFA posture, audit visibility, and support contacts.
Enterprise Operations Overview
Merchant Team & Access Management
Route: /merchant-team
Merchant Team & Access Management gives operators a governed view of organization, departments, roles, permissions, administrators, finance, operations, support, compliance, developers, executive contacts, MFA posture, and audit visibility.
Current recommendation: Review team posture with merchant administrators while keeping user creation, invitations, permission mutation, and role changes disabled.
Organization
readyVisible
Organization structure is visible for access review.
Roles and permissions
readiness onlyReadiness only
Role posture is visible without mutation.
MFA posture
human review requiredHuman review
MFA posture requires identity/security review.
Access mutation
blockedBlocked
No users, invites, permissions, or roles are changed.
Merchant organization access is visible without mutation.
The surface covers organization, departments, roles, permissions, and administrators.
Organization
readiness onlyOrganization posture is visible for access management review.
No user creation, invitation, role assignment, permission update, or organization mutation occurs.
Departments
readiness onlyDepartments posture is visible for access management review.
No user creation, invitation, role assignment, permission update, or organization mutation occurs.
Roles
readiness onlyRoles posture is visible for access management review.
No user creation, invitation, role assignment, permission update, or organization mutation occurs.
Permissions
readiness onlyPermissions posture is visible for access management review.
No user creation, invitation, role assignment, permission update, or organization mutation occurs.
Administrators
readiness onlyAdministrators posture is visible for access management review.
No user creation, invitation, role assignment, permission update, or organization mutation occurs.
Merchant teams can review function-level access posture.
Finance, operations, support, compliance, developers, executive contacts, MFA posture, and audit visibility remain read-only.
Finance
human review requiredFinance is available for team access governance.
No invitation, permission mutation, notification, support ticket, or workflow execution occurs.
Operations
human review requiredOperations is available for team access governance.
No invitation, permission mutation, notification, support ticket, or workflow execution occurs.
Support
human review requiredSupport is available for team access governance.
No invitation, permission mutation, notification, support ticket, or workflow execution occurs.
Compliance
human review requiredCompliance is available for team access governance.
No invitation, permission mutation, notification, support ticket, or workflow execution occurs.
Developers
human review requiredDevelopers is available for team access governance.
No invitation, permission mutation, notification, support ticket, or workflow execution occurs.
Executive contacts
human review requiredExecutive contacts is available for team access governance.
No invitation, permission mutation, notification, support ticket, or workflow execution occurs.
MFA posture
human review requiredMFA posture is available for team access governance.
No invitation, permission mutation, notification, support ticket, or workflow execution occurs.
Audit visibility
human review requiredAudit visibility is available for team access governance.
No invitation, permission mutation, notification, support ticket, or workflow execution occurs.
Advisory intelligence for human-reviewed enterprise operations.
This AI advisor explains readiness posture, evidence, blockers, and next human review actions using safe static operating context.
The advisor cannot execute providers, move money, post ledgers, mutate customers or merchants, create workflows, send notifications, create tickets, perform KYB/KYC/AML/sanctions checks, make regulated decisions, or expose credentials.
Summarize role and permission posture for human review.
Flag MFA and audit visibility gaps without changing access.
Keep invitations, user creation, and permission updates disabled.
Read-only enterprise operations timeline for human review.
The timeline records readiness milestones, establishment of this capability, pending human reviews, and blocked execution boundaries.
Identity
Organization platform established
Organization persistence and UI foundations exist upstream.
Phase V
Merchant team capability established
Merchant team posture is connected as read-only.
Review
Access owner review pending
Team and role review remains human-led.
Safety
Permission mutation not authorized
Permissions and invitations are blocked.
Enterprise capability navigation stays connected and non-executing.
These links are navigation only across executive, merchant, customer, treasury, compliance, operations, merchant account, onboarding, activation, ecosystem, and AI surfaces.
Merchant Team & Access Management remains read-only, advisory, and governed.
This surface does not execute payments, refunds, providers, ledger entries, settlements, treasury movement, merchant activation, merchant mutation, customer mutation, workflow execution, notification execution, ticket creation, KYB, KYC, AML, sanctions, regulatory decisions, autonomous AI, credential exposure, API key exposure, secrets, SQL, Prisma changes, or dependencies.
paymentExecutionEnabled
false
refundExecutionEnabled
false
providerExecutionEnabled
false
ledgerExecutionEnabled
false
settlementExecutionEnabled
false
treasuryMovementEnabled
false
merchantActivationEnabled
false
merchantMutationEnabled
false
customerMutationEnabled
false
workflowExecutionEnabled
false
notificationExecutionEnabled
false
ticketCreationEnabled
false
kybExecutionEnabled
false
kycExecutionEnabled
false
amlExecutionEnabled
false
sanctionsExecutionEnabled
false
regulatoryDecisioningEnabled
false
autonomousAiEnabled
false
providerCredentialExposureEnabled
false
apiKeyExposureEnabled
false
secretsExposed
false
prismaSchemaChanged
false
sqlFilesCreated
false
dependenciesAdded
false
