Permission management

Permission management
Configure Hub roles, assign operations, and manage team member accounts for secure payment platform access

Solidgate Hub provides role-based access control so merchants can decide who can view data and which actions each team member can take.

Access control lives in Account settings and is split across two pages.

  • Roles lists predefined system roles, lets you create and manage custom roles, and shows the operations each role can perform
  • User management invites team members, assigns roles, and handles status, password, and two-factor authentication (2FA) actions

Administrators can reset passwords and 2FA, and delete, block, or unblock users when access needs change. They can also help handle access for lockouts and sign-in issues.

To maintain account security, 2FA is turned on by default and cannot be turned off. Merchant admins can reset it for users on the User details page when needed.

Roles and access

A role is a named set of operations. An operation is a single Hub action, such as viewing orders, refunding a payment, managing API keys, or inviting users. Operations are grouped by Hub section, including Payments, Developers, Account settings, and Cards or APMs subgroups where those pages exist.

The Hub supports two role types.

  • Predefined roles are system roles with a fixed set of operations. You can view their operations and duplicate them into a custom role, but you cannot edit or delete them.
  • Custom roles are merchant-defined. You select any combination of public operations, set a name and description, and manage the role over time.

You can assign one or more roles to a user within an account. Effective permissions are the union of all operations from every assigned role. Assign only the roles each team member needs for their duties.

Role management includes creating, editing, duplicating, and deleting custom roles. It is available to Merchant admin by default. You can grant the same operations to another role through a custom role.

Predefined roles

Predefined roles cover common team functions. Open Account settings > Roles to browse cards for each role, then open a role to inspect its full list of operations.

Typical predefined roles include the following.

  • Merchant admin has the broadest access across payments, billing, fraud prevention, finances, developers, account settings, and user management.
  • Team lead covers day-to-day operations on orders and billing data. Access is narrower than Merchant admin.
  • Manager focuses on operational work across orders and billing with more limited financial and advanced settings access.
  • Analyst is read focused and has access to dashboards, orders, billing data, reports, and analytics.
  • Support tier 1, Support tier 2, and Support tier 3 provide leveled support access. Higher tiers add dispute handling and related actions.
  • Dispute support focuses on dispute resolution and related order and risk work.
  • Developer covers technical tools such as channels, Apple Pay domains, API limits, and API logs, without business or financial operations.
  • Alert manager focuses on prevention alerts, fraud notifications, and related risk signals.
  • Finance manager covers settlements, monthly reports, billing financial views, and related reporting.
  • Authorized signatory is limited to agreements, legal entities, questionnaires, and document signing.

To view operations for a predefined role

  1. Go to Account settings > Roles.
  2. In Predefined roles, click on the role card.
  3. Expand each operations group to review the allowed actions.

Use Duplicate on a predefined role when you need a starting point for a custom role with the same operations.

Custom roles

Custom roles let you define exactly which operations a team member can perform. You select operations by section, set a name, and add a description. Custom roles are owned by the merchant account. Solidgate does not change their operation set automatically when system roles change.

Create custom role

To create a custom role

  1. Go to Account settings > Roles.
  2. Click on New role.
  3. Enter a Name and optionally a Description.
  4. Expand each operations section and select the actions to include.
  5. Click on Create to save the role.

After you create a role, assign it in User management. You can combine custom roles with predefined roles on the same user.

Edit custom role

To edit a custom role

  1. Go to Account settings > Roles.
  2. In the Custom roles table, click on the role name or the Edit icon.
  3. Update the name, description, or operations as needed.
  4. Click on Update to apply the changes.

Duplicate role

You can duplicate a custom role from the Custom roles table, or duplicate a predefined role from its details panel. The copy appears as Copy of followed by the original role name, keeps the same operations, and becomes a custom role you can edit.

To duplicate a custom role

  1. Go to Account settings > Roles.
  2. Find the role in the Custom roles table.
  3. In the Actions column, click on the three-dot menu and select Duplicate.
  4. Open the copy to rename it or adjust operations.

Delete custom role

To delete a custom role

  1. Go to Account settings > Roles.
  2. Find the role in the Custom roles table.
  3. In the Actions column, click on the three-dot menu and select Delete.
  4. Click on Delete to confirm.
A role cannot be deleted while users are assigned to it. Reassign or remove all assigned users first. The role details panel lists assigned users so you can update them before deleting.

User management

User management is where you invite team members, assign roles, and manage account status. Filter the list by email, role, or status, then open a row to work with User details.

Invite user

To invite a user

  1. Go to Account settings > User management.
  2. Click on Invite user.
  3. Enter the email address and select one or more roles.
  4. Send the invitation and wait for the recipient to accept it before the link expires.

If an invitation expires and the account stays inactive, send a new invitation from User management.

Assign roles

To assign or change roles

  1. Go to Account settings > User management.
  2. Click on the user email to open User details.
  3. In the Roles section for the account, select or clear roles in the multi-select list.
  4. Click on Save.

A user can hold several roles at once, including a mix of predefined and custom roles. Permissions accumulate across all selected roles.

Manage user access

On User details, Merchant admins and roles with the matching operations can take these actions.

  • Block or unblock the user and record a block reason when needed
  • Reset password so the user can set a new password
  • Reset 2FA so the user can enroll an authenticator again
  • Delete user to remove access from the current Hub account only
Blocking a user can affect every Hub account that person can access. If someone should leave only one merchant account, use Delete user on that account instead of blocking.

Audit log

Audit log records actions performed by users within Hub and provides a single source of truth for activity tracking. It captures who performed an action, what happened, where it occurred, and when, including data changes.

This supports security monitoring, analysis of user activity, and compliance requirements.

To view logged actions

  1. Go to Account settings > Audit log.
  2. Find the required user in the list.
  3. Optionally, use filters to narrow the results.
  4. Click on Apply, and see the data update instantly.

Each audit log entry includes user role, user email, IP address, object ID, object type, action description, and timestamp. Logs become available within five seconds after an action, providing near-real-time visibility into activity.

Use the audit log to identify changes made to entities, track actions by role, review entity change history, and analyze login activity.


Handle access

Solidgate Hub applies several security measures to protect accounts, including role-based access management, automatic lockouts, mandatory 2FA, and Google sign-in.

Account lockout

After multiple failed login attempts, the account locks automatically for 30 minutes.

You can restore access in these ways.

  • If you remember your password, wait 30 minutes for automatic unblocking or ask a Merchant admin to unblock the account in the User management section.
  • If you have issues with your password or 2FA, ask a Merchant admin to reset your password or 2FA in the User management section.
  • If the standard methods do not work, contact us to restore account access.

2FA

2FA is required for all roles by default. To avoid sign-in issues, confirm that your authenticator app is set up correctly and that your device time is synchronized.

These are common 2FA issues and how to resolve them.

  • Invalid verification codes Verify that you are using the correct authenticator app and that your device time is set automatically. Turn on the automatic date and time in your device settings, then try again.
  • Lost or broken authenticator device Ask the Merchant admin to reset 2FA. After the reset, set up 2FA again on your new device.
  • Moving 2FA to a new device Ask the Merchant admin to reset 2FA, then complete the setup on the new device.
  • Errors during 2FA setup First, ask the Merchant admin to reset 2FA, then try setting up 2FA again. If the issue continues, contact us to restore account access.

Google sign-in

Solidgate Hub supports Google sign-in to simplify the login process. You can sign in using your Google account instead of entering your email and password. To use this option, first link your Google account.

To link your Google account

  1. Go to Profile > Personal.
  2. Click on Link your Google account.
  3. Follow the instructions to link your Google account.

Once linked, you can select Sign in with Google on the Hub sign-in page to access your account without entering credentials. If you lose access to your Google account, you can still sign in with your password or contact the Merchant admin to reset your Google sign-in.


Looking for help? Contact us
Stay informed with Changelog