Synchronizing
Architectural Primitives

Roles and access

Aegis has three staff roles inside your tenant and two applicant-side roles on a single application. What a person can do is decided by their role, and separation between the maker and the checker is built into it.

Staff roles
Analyst
Reviews and scores cases
MLRO
Adds screening exceptions
Admin
Adds configuration and approval
Applicant-side roles
Applicant (owner)
The counterparty
Teammate
Invited to help complete

What each role can do

Analyst is the base staff role. MLRO and Admin each add to it, but neither includes the other: an admin cannot record a screening exception, and an MLRO cannot configure an intake. Assign both where you need both. Tenant provisioning, branding, and API key issuance sit with Aurora Edge and are covered in Administration.

RoleScopeCan do
AnalystOne tenantReview the case queue, run and confirm screening and scoring, record analyst sign-off, and propose decisions (the maker).
MLROOne tenantEverything an analyst can, plus record attributed screening exceptions: a named officer signing off on a screening result that would otherwise block approval.
AdminOne tenantEverything an analyst can, plus manage staff users, configure forms and risk engines, attach intake labels, approve decisions (the checker), and manage applications.
Applicant (owner)Their own applicationComplete the form, upload documents, invite teammates, and submit.
TeammateA shared applicationHelp fill the form and upload documents. Only the owner may submit.

How people sign in

Staff sign in with email and password, with multi-factor authentication available. Applicants and teammates never have a password: they sign in only through a secure single-use link that Aegis issues.

Authorisation is derived, not requested
Authorisation is decided from the signed-in identity, never from the request, so a user cannot escalate their own access or reach another tenant's data. Role or tenant changes take effect immediately and invalidate stale sessions. See Security and compliance.

Separation of duties

Two role boundaries carry real weight in the workflow rather than being administrative convenience.

Maker-checker

An analyst proposes an approval. A different admin countersigns it. One person cannot do both halves.

Screening exceptions

Only an MLRO can allow a case to proceed past a blocking screening result, and the exception is attributed to them in the audit record.

Both are covered in detail in Onboarding lifecycle and Screening.