MOONEUM

Team & permissions

ForBusiness ownersFinance teams

Owners and members

The person who creates an organization is its owner and starts with full access to every product and permission level. Owners can invite teammates from any product's Settings → Team page and choose exactly what they can do.

Permission levels

Permissions are granted per product and per feature — a teammate might get Initiate on Pay but only View on Treasury. From least to most access:

LevelWhat it allows
ViewRead-only access to that feature's data
InitiateCreate drafts — a payment, an order, a borrow request — that still need approval
ApproveApprove or reject other people's submissions
PublishFull control, including managing that product's team and developer access

Two grants deserve special care:

  • Wallets at Publish (Treasury) is the platform's highest-trust gate — it's required to pair Signer devices and to complete the final signing step of approval chains. Keep it to the small set of people allowed to actually move funds.
  • Team at Publish (per product) lets a member manage that product's grants — effectively a product-level admin.

Deciding exactly what to grant someone is easier with the full permissions reference — every grantable feature across the platform, generated directly from the same registry the grant options come from, so it can never list something you can't actually grant.

Approval chains

Any action above a configured threshold requires sign-off before it executes on-chain. You define approval chains as part of your policies — for example, "any payment over $10,000 needs 2 of 3 named approvers." Pending approvals appear on the Approvals page in the relevant product for everyone with Approve access, and the final publish step is completed by a wallets-Publish holder.

Multiple organizations

One account can belong to multiple organizations (e.g. if you consult for more than one company). Switch between them with the org switcher in any product's sidebar — sign-in is shared across every product and org subdomain.