> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rails.wayex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Team & roles

> How team membership works and how roles govern what each person can see and do in the console.

The console is operated by your own staff. Each person has their own account and a **role** that governs
what they can see and do.

## Team members

Your team is made up of the people at your organisation who use the console. The first administrator is
activated from an invitation link Wayex sends by email; opening it lets them set a password and activate
the organisation. To add team members or change a member's role, contact Wayex — membership and roles are
provisioned by Wayex, not managed from the console. Newly provisioned members still set their own
permanent password the first time they sign in.

Everyone signs in with their own [email and password](/console/overview#signing-in).

Membership belongs to one tenant account. If the same staff member operates multiple accounts,
access is granted and audited independently in each account.

## Roles

Each member has one role. Roles are hierarchical — a higher role includes everything a lower one can do.

| Role         | Can do                                                                                                                                       |
| ------------ | -------------------------------------------------------------------------------------------------------------------------------------------- |
| **Viewer**   | Read-only. View direct-route resources and enabled Treasury balances, funding, settings, and transactions.                                   |
| **Operator** | Viewer access plus customer/route actions, API key management, and enabled Treasury beneficiary, payout, conversion, and withdrawal actions. |
| **Admin**    | Operator access plus Treasury funding instruments and stablecoin destinations.                                                               |

<Note>
  There is no separate approval step in the console — a member whose role permits an action performs
  it directly. That includes your pricing and fees, which operators and admins update from the
  console's Fees page.
</Note>

Money actions and sensitive destination/key changes require a fresh MFA step-up in the console. This
confirms the acting user; it does not replace server-side tenant, role, policy, limit, or balance checks.

The console adapts to your role automatically. Where an action is not available to you, the button is
hidden or disabled and the screen explains why — for example, a viewer sees a "read-only access" notice in
place of create actions.

## Audit

Sensitive actions are recorded for audit. When recording a note on an action, keep it short and never
include secrets or personal information.
