Role-based access control (RBAC)
RBAC lets your organization assign a defined persona to each Dashboard user so that capabilities in Analyze, Inspect, and Encompass import are gated by job function. Each user sees and can act on only what their role requires, giving lending teams least-privilege access by design, a clear auditable structure for compliance reviews, and a faster onboarding experience where new users are productive with the correct permissions from their first login.
System Roles is enabled per organization by your Ocrolus account manager. Contact your account manager to request enablement and to align on a duplicate-email resolution strategy before go-live.
RBAC offers the following capabilities:
Six roles that map to common lending-team structures. No configuration required to start.
Permissions control specific actions: edit income, create conditions, import to Encompass, and more.
Admins assign and reassign roles right on the Team page in Organization Settings.
Restrict powerful actions to the roles that should have them, without blocking day-to-day work.
Key concepts
| Term | Definition |
|---|---|
| System role | A pre-built permission profile assigned to a user. Each role bundles a specific set of capabilities across Analyze, Inspect, and Encompass import. |
| Permission | A specific action that a role can or cannot perform. For example, editing income values or importing conditions to Encompass. |
| Duplicate email | A conflict that occurs when an Encompass user's email address already exists in a different Ocrolus organization, requiring resolution before account linking completes. |
System roles
RBAC offers six system roles, each reflecting a real seat on a lending team. Assign the role that matches each user's day-to-day responsibilities.
| Role | Primary responsibility | Access summary |
|---|---|---|
| Loan Officer | Originates and sells loans | Views income but cannot edit values or set conditions |
| Processor | Gathers and clears conditions | Imports income, adds notes, uploads documents |
| Underwriter | Makes credit decisions | Full Inspect review; sets and waives conditions |
| Loan Officer (LO) / Processing Assistent | Supports LOs and processors | Read-only or limited edit, depending on org configuration |
| Closer / Funder | Reviews the final loan package | Minimal access to Inspect and Analyze data |
| Lending Operations Manager | Oversees the whole team | Full admin: configures access, audits usage |
Capability matrix
The table below shows the access level each role has for high-impact capabilities. Verify the exact configuration against your organization's live permissions before go-live.
| Capability | Loan Officer | Processor | Underwriter | LO Asst. | Closer | Lending Ops Mgr |
|---|---|---|---|---|---|---|
| Delete documents | No access | Read and write | Read and write | No access | No access | Full control |
| Edit income values (Analyze) | Read only | Read and write | Full control | Read only | Read only | Full control |
| Add comments | Read and write | Read and write | Read and write | Read and write | Read only | Full control |
| Import income to Encompass | No access | Read and write | Read and write | No access | No access | Full control |
| Import Inspect to Encompass | No access | No access | Read and write | No access | No access | Full control |
| Create manual conditions | No access | Read and write | Full control | No access | No access | Full control |
| Change condition status / waive | No access | No access | Full control | No access | No access | Full control |
| Import conditions to Encompass | No access | No access | Read and write | No access | No access | Full control |
| View Inspect | Read only | Read only | Full control | Read only | Read only | Full control |
| Org-level configuration edit | No access | No access | No access | No access | No access | Full control |
Use cases
Each system role maps to a real workflow on the lending team. Here is how permissions play out in practice.
- Loan officers get a clean and read-only income view. Review Analyze income data without any risk of editing calculated values or triggering actions reserved for underwriting.
- Processors can import and annotate without touching conditions. Import income to Encompass, upload supporting documents, and add notes, without access to condition management, which stays restricted to underwriters.
- Underwriters have full control over conditions. Set, edit, and waive conditions in Inspect and push them to Encompass. No other role has this level of access by default.
- Lending Ops Managers onboard new users instantly. Assigning a persona takes one action in Organization Settings. A new user is productive with the correct permissions from their first login.
- Access reviews and compliance audits are straightforward. Every user's effective permissions are visible in the Roles table at a glance, making periodic access reviews quick and auditable.
Known issues
The current release has a few boundaries worth knowing before you roll out. Most are already scoped for an upcoming phase.
| Limitation | Detail |
|---|---|
| No custom roles | Only the six system personas are available. Org-specific permission sets are planned for a future phase. |
| No pre-login role assignment | A user profile is created on first login. Admins cannot pre-assign a role before that point. |
| Broad default on first login | First-login users receive a default role that grants broad access until an admin assigns a restricted role. |
| No admin-side Encompass user creation | Encompass users are created by webhook or by logging in, not from the Ocrolus admin page. |
| No role-assignment reminders | There is no automated prompt to assign a role after a user's first login. |
See also
Step-by-step instructions for assigning a system role to a user in Organization Settings.
Configure your Encompass integration before enabling System Roles for your org.
Understand how conditions work in Inspect and which roles can create, edit, or waive them.
Learn how income calculations work in Analyze and which roles can view or edit values.
Updated about 1 hour ago