Roles and access
Aegis has three staff roles inside your tenant and two applicant-side roles on a single application. What a person can do is decided by their role, and separation between the maker and the checker is built into it.
What each role can do
Analyst is the base staff role. MLRO and Admin each add to it, but neither includes the other: an admin cannot record a screening exception, and an MLRO cannot configure an intake. Assign both where you need both. Tenant provisioning, branding, and API key issuance sit with Aurora Edge and are covered in Administration.
How people sign in
Staff sign in with email and password, with multi-factor authentication available. Applicants and teammates never have a password: they sign in only through a secure single-use link that Aegis issues.
Separation of duties
Two role boundaries carry real weight in the workflow rather than being administrative convenience.
Both are covered in detail in Onboarding lifecycle and Screening.