System roles and permissions

Last updated: August 18, 2026

ComplyAdvantage Mesh uses role-based access control (RBAC). What a user can see and do is determined by the roles assigned to them in the account they are working in, not by the individual user record.

Every account comes with three system roles: Analyst, Supervisor, and Admin. These cover the most common ways compliance teams divide work. Alongside them, you can build your own roles with exactly the permissions you need. See Creating and managing custom roles.

How access is put together

Three things define access in Mesh:

  • Permission. A single action, such as viewing a case or creating a screening configuration.

  • Role. A named set of permissions. System roles are provided by ComplyAdvantage; custom roles are created by you.

  • Account. Roles are assigned per account. A user who works in more than one account in your organization can hold different roles in each. See Switching between accounts.

A user can hold more than one role in the same account. Permissions are additive, so the user gets the combined permissions of every role assigned to them. Removing access means removing the role that grants it, not adding a restriction on top.

Base and action permissions

Most product areas need two permissions to work, not one.

Base permissions open the area. Without the base permission, the individual action permissions in that area do nothing. They read as Access to base customer screening functionality or Access to base customer monitoring functionality.

Action permissions allow a specific operation inside it, such as Create and screen customers or Monitor and unmonitor customers.

So a role that onboards and screens customers needs the base customer screening permission and the create-and-screen permission. Either one alone will fail.

The three system roles

Role

Intended for

Access in summary

Analyst

Day-to-day investigation work

Review and action the queue: customers, alerts, and cases

Supervisor

Team leads and reviewers

Everything an Analyst can do, plus insights and exports

Admin

Platform administrators

Everything a Supervisor can do, plus configuration, users, and roles

Good to know - System roles maintain themselves.

System roles cannot be edited or deleted, and they are marked with a lock icon in the roles list. As features are released, ComplyAdvantage adds the relevant new permissions to each system role automatically. Custom roles do not update this way: when a new permission becomes available, you decide whether to add it to each of your own roles.

What each role covers

The table below is a guide to the shape of each role rather than a complete list. Permissions are added as the platform grows, so treat the roles and permissions page in Mesh as the authoritative record.

Area

Analyst

Supervisor

Admin

View, create, and screen customers

Yes

Yes

Yes

Turn customer monitoring on and off

Yes

Yes

Yes

View and update alerts and risks

Yes

Yes

Yes

View, update, assign, and label cases

Yes

Yes

Yes

Insights dashboards

No

Yes

Yes

Exports and downloads

No

Yes

Yes

View case workflows

No

Yes

Yes

Risk models, screening configurations, and scenario configurations

No

No

Yes

Create and update case workflows

No

No

Yes

Webhooks and email notification configurations

No

No

Yes

Add users, assign roles, and create custom roles

No

No

Yes

Check exactly what a role grants

The roles and permissions page shows every permission in the platform and whether a given role has it.

  1. Select Settings from the main navigation.

  2. Go to Access management and select Roles and permissions.

  3. Select a role to open its details. To see the full catalog of permissions, select the Admin role, which has all of them enabled.

  4. Toggle Show only granted permissions to hide everything the role does not grant.

Important to know - Some permissions depend on others.

A permission can require another permission to work. Viewing a case, for example, is a prerequisite for moving it to another stage. Where a dependency exists, Mesh marks the permission with an icon and selects the permissions it depends on for you. A few permissions also depend on the products enabled for your account, so they only appear if that product is active.

Permissions for specific case types

Access to cases is controlled per case type, so a role can be scoped to customer screening, customer monitoring, payment screening, or transaction monitoring work. Users with the Admin role keep access to every case type. For how to configure this, see Permissions by case type.

Organization-level permissions

A small set of permissions covers management across every account in your organization rather than within one account, such as viewing all accounts and managing roles at organization level. These sit outside the three system roles, so no system role includes them.

Role names and language

System role names are shown in the language the user has selected, so an Analyst in a French-language session sees the French name for the role. Custom role names always display exactly as you configured them.

Next steps

  • Creating and managing custom roles walks through building a role from a chosen set of permissions. Duplicating a system role is the quickest starting point when you want an Analyst or Supervisor with one or two changes.

  • Managing users covers adding users to an account and updating their roles, including in bulk.

  • Permissions by case type covers restricting a role to specific case types.