Airwallex User Access Management lets you control what users can do across your organisation and within individual accounts.
You can use User Management to:
- Invite and remove users.
- Assign default or custom roles.
- Select the accounts each user can access.
- Review and manage user permissions.
- Manage employment entities for users.
For information about streamlining user onboarding and management with an HRIS integration, see Airwallex and HRIS integrations.
User and role management
To view all users in your organisation, go to Users.
To review the permissions assigned to a role, go to Users > Roles, then select the role.
The new user model separates permissions into two levels:
- Organisation-level permissions apply across your organisation.
- Account-level permissions apply only to the accounts the user can access.
Roles combine organisation-level and account-level permissions. A user’s role does not automatically give them access to every account in the organisation. Account access is assigned separately.
Organisation-level and account-level permissions
Organisation-level permissions
Organisation-level permissions apply across the organisation. Depending on the role, they can include the following:
| Area | Permission | What it enables |
| Expenses | Expense admin | View and edit expenses and reimbursements, and manage expense settings and approval workflows. |
| Expenses | Expense submitter | Submit expenses and reimbursements. |
| Expenses | Expense approver | Approve expenses and reimbursements when assigned as an approver. |
| Bills | Bill admin | View and edit bills, and manage bill settings and approval workflows. |
| Bills | Bill submitter | Submit bills for approval. |
| Bills | Bill approver | Approve bills when assigned as an approver. |
| Vendor management | Own vendors | Create and edit vendors owned by the user or assigned to them. |
| Vendor management | All vendors | View and manage all vendors in the organisation. |
| Vendor management | Settings and approvals | Manage vendor settings and approval workflows. |
| Requests | Request admin | Manage request settings and approval workflows. |
| Requests | Request submitter | Create and submit requests for approval. |
| Requests | Request approver | Approve requests when assigned as an approver. |
| Cards | Cardholder | Hold a company or employee card in any account in the organisation. |
| User Management | Users and roles | View or manage users and roles, including creating custom roles where permitted. |
| User Management | Invitations | Invite or remove employees, admins, developers, or owners where permitted. |
| Connections | Organisation connections | View or manage organisation-level connections. |
| Organisation settings | Organisation and legal entities | View or manage organisation information and legal entities where permitted. |
| Plan and billing | Billing and subscription | View or manage subscription and billing information where permitted. |
| Developer | API keys and webhooks | View or manage organisation-level developer configurations where permitted. |
| Payees | Payee management | Create and edit payees for the organisation. |
Some permissions are available only when the related Airwallex product or feature is enabled for your organisation.
Account-level permissions
Account-level permissions apply only to the accounts the user can access.
Business Accounts
Depending on the account type and the permissions assigned, Business Accounts can include:
| Permission | What it enables |
| Borderless Cash accounts — view balances | View cash balances. |
| Borderless Cash accounts — view transactions | View cash transactions. |
| Yield accounts — view | View Yield account information. |
| Credit accounts — view | View Credit account information. |
| Move funds | Move funds to or from Yield or Credit accounts where permitted. |
| Repay | Repay Credit balances where permitted. |
Moving funds to or from Yield or Credit accounts is controlled by the user’s internal-transfer edit permission on the source account. The destination account is not checked for this permission.
A user who has permission to view cash balances, cash transactions, Yield accounts, or Credit accounts can see the Business Accounts navigation item.
Other account permissions
| Area | Permission | What it enables |
| Linked bank accounts | View and manage | View, create, and remove linked bank accounts, and initiate direct-debit funding where available. |
| Airwallex Pay | Pay via Airwallex Pay | Make purchases using the account’s business account balance where Airwallex Pay is accepted. |
| Global Accounts | View, create, edit, and close | View, create, edit, or close domestic and international bank accounts where permitted. |
| Conversions | View and create | View conversion records and make FX conversions. |
| Transfers | Internal transfers — view and edit | View or create transfers between accounts in the same organisation. |
| Transfers | External transfers — view and edit | View or create transfers to external payees. |
| Transfer approvals | View and manage | View and manage the transfer approval workflow. |
| Transfer methods | View and manage | View or manage additional transfer methods that require declaration or limit management. |
| Transfer settings | View and edit | View or edit transfer settings. |
| Cards | Card admin | Create and manage company and employee cards in the account. |
| Payments | View and manage | View or manage payments. |
| Risk | View and manage | View or manage risk settings, rules, dashboards, and watchlists. |
| Disputes | View and manage | View or manage disputes and issue refunds. |
| User Management | Users and roles | View or manage users assigned to the account. |
| Account | Account groups | Create and edit account groups where permitted. |
| Account | Transaction RFI | Review and respond to transaction-related requests for information. |
| Account | Account details and settings | View or edit account and contact information. |
| Connections | Account connections | View or manage account-level connections. |
| Developer | API keys and webhooks | Set up account-level integrations and manage API keys and webhooks where permitted. |
Some permissions are available only when the related Airwallex product or feature is enabled for your organisation or account.
Default roles
The new user model includes seven default roles:
- Owner
- Admin
- Finance Admin
- Finance Manager
- Bookkeeper
- Employee
- Developer
A role determines the permissions available to a user. The accounts they can access are assigned separately.
Employee
Employees can:
- Submit expenses, reimbursements, and bills.
- Be assigned as approvers for expenses and bills.
- Hold virtual or physical cards when issued one.
Employees do not have account access by default. Employee is the recommended standard role for most employees.
Bookkeeper
Bookkeepers can manage spend and view Business Accounts, conversions, and transfers for accounting purposes.
Finance Manager
Finance Managers can:
- View Business Accounts and transactions.
- Create FX conversions and transfers.
- Create Global Accounts.
- Manage spend.
- Issue cards to new and existing users.
Finance Admin
Finance Admins can do everything Finance Managers can do, plus:
- Invite users.
- Set up connections.
- Create and edit transfer approval workflows.
- Link bank accounts.
Admin
Admins can do everything Finance Admins can do, plus:
- Invite developers and other admins.
- Create new accounts and entities where permitted.
Owner
Owners have the broadest default access. They can perform critical actions in the accounts they can access and manage organisation-wide access.
Owners can also:
- Invite other owners.
- Manage transfer approval workflows where permitted.
- Manage ownership changes through an ownership-change support request.
An Owner does not automatically have access to every account in the organisation. Account access must still be assigned.
Developer
Developers can set up Airwallex integrations and manage API keys and webhooks that grant access to Airwallex resources.
API keys can provide access to sensitive resources. Only create and share API keys with people who need them for their work.
Invite a new user
To invite a new user:
- Go to Users.
- Select Invite user.
- Enter the user’s details.
- Select their role.
- Select the accounts they should be able to access.
- Send the invitation.
Depending on the invitation flow available to your organisation, you can either:
- Apply the same role to all selected accounts; or
- Assign different roles for different accounts.
Organisation-level permissions apply across the organisation. Account-level permissions apply only to the accounts selected for the user.
Change account ownership
To add a new owner to an organization, follow this guide.
Custom roles
A custom role is a role created by an Owner, Admin, or Finance Admin by selecting specific organisation-level and account-level permissions.
On the role-creation page, permissions for cash, Yield, and Credit are grouped under Business Accounts. Transfer permissions are separated into internal transfers and external transfers. Payee management is an organisation-level permission.
Create a custom role
- Go to Users > Roles.
- Select Create role.
- Enter a role name and, optionally, a description.
- Select Next.
- Select the organisation-level and account-level permissions for the role.
- Select Create role.
Assign only the permissions users need to perform their responsibilities.
Change a custom role’s permissions
- Go to Users > Roles.
- Find the custom role you want to change.
- Select the More actions menu, then select Edit role.
- Update the permissions.
- Select Save changes.
Permission changes take effect immediately for all users assigned to the custom role.
Delete a custom role
- Go to Users > Roles.
- Find the custom role you want to delete.
- Select the More actions menu, then select Delete role.
- Confirm the deletion.
Deleting a custom role affects all users assigned to it immediately. If it was a user’s only role, they will no longer have the permissions provided by that role.
Duplicate a role
You can duplicate a role to use it as the starting point for a new custom role:
- Go to Users > Roles.
- Find the role you want to duplicate.
- Select the More actions menu, then select Duplicate role.
- Complete the custom-role creation flow.
- Select Create role.
Employment entity
Each user has an associated employment entity. This is the entity that employs the user.
The employment entity is used as the default entity for allocating the user’s reimbursements. It also determines the accounting values the user sees when submitting a reimbursement report.
Admins can change a user’s employment entity in Users.
Review user access regularly
Review users, roles, and account access regularly to help ensure that each user has only the access they need.
When a user changes role or responsibilities:
- Update or remove roles they no longer need.
- Review the accounts they can access.
- Review their Business Accounts, internal-transfer, external-transfer, and payee-management permissions.
- Review any API keys or integrations they manage.
- Remove users who no longer need access.