Roles and Permissions
Default Roles and their Permissions
Default roles have been created to enable faster onboarding. Members who belong to default roles will be automatically added to all new wallets and enterprises in the organization with the respective permissions. The default roles have the following permissions across all wallets and enterprises.
Organization Admin: a member managing user permissions and access
Enterprise Admin: a member creating wallets within the enterprise, managing enterprise-level policies
Wallet Admin: a member managing wallet-level policies and whitelist
Wallet Spender: a member initiating transactions
Wallet Trader: a member initiating trades, can also view all wallets in the enterprise
Video ID User: a member undergoing Video ID verification with BitGo’s Trust team, allowing them to authorize sensitive operations that require identity confirmation
Viewer: a member view wallet balances and transactions
Auditor: a member viewing activity logs
For more information about roles and permissions, please refer to the Roles and Permissions Matrix.
Creating Custom Roles
If you determine that custom roles need to be created for your organization, this can be done by the Organization Admins. Click Create Role at the bottom of the page. Once the custom role is created you can add members to it. This will require approval if your organization has more than one Organization Admin.
Click on the Roles tab
Click on Create Role
Name the Role
Select the permissions that you want this role to have
Select the Enterprises that you want these permissions to apply to
All Enterprises: all enterprises that exist today and all future enterprises that are added the organization
Select Enterprises: if you only want this role to apply to certain enterprises
Choose to grant access to all wallets, or individually pick specific wallets for each enterprise:
All Wallets: all wallets that exist today and all future wallets that are added the enterprise
Select Wallets: if you only want certain wallets within the respective enterprise
When to Use Default vs. Custom Roles
Here are some things to consider when determining whether to leverage BitGo’s default roles for your organization or create custom roles:
Do the default roles have the correct set of permissions?
Should members in these roles have these permissions across enterprises and wallets, now and in the future?
Are the default roles sufficient?
Does my organization require a unique combination of permissions and/or wallet and enterprise access?
Updating Roles
Only ONE update can be made to a role at a time. This update must be approved before other updates can be made to the same role. For example, if you want to add members, remove members and update permissions, you will only be able to do one after the other.
Note:
Members must already exist to be added to a role in the Roles tab. If they are not in the Organization yet, they can be added from the Members tab.
Every member must have at least one role to remain in an Organization.
Removing Members
Members can be removed from your organization on the Members tab of the Admin Console. Click Edit Member next to the member that you wish to remove then click Remove Member from Organization.
A note on self-custody wallets:
If you are removing a member who is the last key holder of a self-custody wallet, removing this user could freeze access to this wallet and funds could be lost. Ensure another member has key access to this wallet before proceeding. See Self-Custody Wallet Sharing for more information.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article