Role-based access control (RBAC)
RBAC lets your organization assign a defined persona to each Dashboard user so that capabilities in Analyze, Inspect, and Encompass import are gated by job function. Each user sees and can act on only what their role requires, giving lending teams least-privilege access by design, a clear auditable structure for compliance reviews, and a faster onboarding experience where new users are productive with the correct permissions from their first login.
System Roles is enabled per organization by your Ocrolus account manager. Contact your account manager to request enablement and to align on a duplicate-email resolution strategy before go-live.
RBAC offers the following capabilities:
Six roles that map to common lending-team structures. No configuration required to start.
Permissions control specific actions: edit income, create conditions, import to Encompass, and more.
Admins assign and reassign roles right on the Team page in Organization Settings.
Restrict powerful actions to the roles that should have them, without blocking day-to-day work.
Key concepts
| Term | Definition |
|---|---|
| System role | A pre-built permission profile assigned to a user. Each role bundles a specific set of capabilities across Analyze, Inspect, and Encompass import. |
| Permission | A specific action that a role can or cannot perform. For example, editing income values or importing conditions to Encompass. |
| Duplicate email | A conflict that occurs when an Encompass user's email address already exists in a different Ocrolus organization, requiring resolution before account linking completes. |
System roles
RBAC offers six system roles, each reflecting a real seat on a lending team. Assign the role that matches each user's day-to-day responsibilities.
| Role | Primary responsibility | Access summary |
|---|---|---|
| Loan Officer | Originates and sells loans | Views income but cannot edit values or set conditions |
| Processor | Gathers and clears conditions | Imports income, adds notes, uploads documents |
| Underwriter | Makes credit decisions | Full Inspect review; sets and waives conditions |
| Loan Officer (LO) / Processing Assistent | Supports LOs and processors | Read-only or limited edit, depending on org configuration |
| Closer / Funder | Reviews the final loan package | Minimal access to Inspect and Analyze data |
| Lending Operations Manager | Oversees the whole team | Full admin: configures access, audits usage |
Role permission matrix
The table below shows the permissions granted per persona. View access is enabled by default for all personas. Only the actions listed below require explicit permission. Verify the exact configuration against your organization's live permissions before go-live.
| Capability | Action | Loan Officer | Processor | Underwriter | LO / Processing Asst. | Closer / Funder | Lending Ops Manager |
|---|---|---|---|---|---|---|---|
| Documents — index page + uploads | |||||||
| Delete forms from the document on index page mortgage.book.form | Delete | No access | No access | No access | No access | No access | Granted |
| Delete the uploaded doc from uploads section mortgage.book.uploaded-doc | Delete | No access | No access | No access | No access | No access | Granted |
| Delete the mixed document from uploads section mortgage.book.mixed-uploaded-doc | Delete | No access | No access | No access | No access | No access | Granted |
| Income — analyze / income screens + BSIC config | |||||||
| Edit income values on analyze / income screens or via API mortgage.book.income | Edit | No access | Granted | Granted | No access | No access | Granted |
| Edit book-level config for BSIC mortgage.book.income.bsic | Edit | No access | Granted | No access | No access | No access | Granted |
| Edit org-level config for BSIC mortgage.org.income.config | Edit | No access | No access | No access | No access | No access | Granted |
| Comments — book level | |||||||
| Add book-level comments from the dashboard book.comment | Edit | Granted | Granted | Granted | Granted | Granted | Granted |
| Delete book-level comments from the dashboard book.comment | Delete | No access | No access | No access | No access | No access | No access |
| Conditions & Insights — inspect workflow | |||||||
| Create manual conditions on the Ocrolus dashboard mortgage.book.inspect.condition | Create | No access | Granted | Granted | No access | Granted | Granted |
| Edit manual conditions on the Ocrolus dashboard mortgage.book.inspect.condition | Edit | No access | Granted | Granted | No access | Granted | Granted |
| Resolve insights from the Ocrolus dashboard mortgage.book.inspect.insight | Edit | No access | Granted | Granted | No access | Granted | Granted |
| Edit or confirm the mapped entity matching mortgage.book.inspect.entity-matching.edit | Edit | No access | Granted | Granted | No access | No access | Granted |
| Encompass / LOS Export — push from Ocrolus back to the LOS | |||||||
| Import income values back to Encompass mortgage.los.book.income | Edit | No access | Granted | Granted | No access | No access | Granted |
| Import insight values back to Encompass mortgage.los.book.inspect.insight | Edit | Granted | Granted | Granted | Granted | Granted | Granted |
| Import conditions back to Encompass mortgage.los.book.inspect.condition | Edit | Granted | Granted | Granted | Granted | Granted | Granted |
| Import the income worksheet back to eFolder in Encompass mortgage.los.book.efolder.worksheet | Edit | Not specified | Granted | Granted | No access | No access | Granted |
| Upload MISMO from the Inspect screen mortgage.book.mismo.create | Create | Granted | Granted | Granted | Granted | No access | Granted |
| Inspect Access — screen + tab visibility | |||||||
| View the Inspect screen mortgage.inspect.view | View | Granted | Granted | Granted | Granted | Granted | Granted |
| View the conditions tab on the Inspect screen mortgage.book.inspect.condition.view | View | Granted | Granted | Granted | Granted | Granted | Granted |
| Permissions granted | 6 of 19 | 14 of 19 | 13 of 19 | 6 of 19 | 8 of 19 | 18 of 19 | |
- Loan Officer income edit is namespaced
mortgage.book.income; view access is granted to all users by default and only the edit action is controlled.
- Source sheet lists Loan Officer document/comment keys without the
mortgage.prefix and BSIC org config asmortgage.org.income.bsic— confirm the canonical namespace before implementation.
- Processor condition edit covers both manual and automated conditions; all other personas cover manual conditions only.
Use cases
Each system role maps to a real workflow on the lending team. Here is how permissions play out in practice.
- Loan officers get a clean and read-only income view. Review Analyze income data without any risk of editing calculated values or triggering actions reserved for underwriting.
- Processors can import and annotate without touching conditions. Import income to Encompass, upload supporting documents, and add notes, without access to condition management, which stays restricted to underwriters.
- Underwriters have full control over conditions. Set, edit, and waive conditions in Inspect and push them to Encompass. No other role has this level of access by default.
- Lending Ops Managers onboard new users instantly. Assigning a persona takes one action in Organization Settings. A new user is productive with the correct permissions from their first login.
- Access reviews and compliance audits are straightforward. Every user's effective permissions are visible in the Roles table at a glance, making periodic access reviews quick and auditable.
Known issues
The current release has a few boundaries worth knowing before you roll out. Most are already scoped for an upcoming phase.
| Limitation | Detail |
|---|---|
| No custom roles | Only the six system personas are available. Org-specific permission sets are planned for a future phase. |
| No pre-login role assignment | A user profile is created on first login. Admins cannot pre-assign a role before that point. |
| Broad default on first login | First-login users receive a default role that grants broad access until an admin assigns a restricted role. |
| No admin-side Encompass user creation | Encompass users are created by webhook or by logging in, not from the Ocrolus admin page. |
| No role-assignment reminders | There is no automated prompt to assign a role after a user's first login. |
See also
Step-by-step instructions for assigning a system role to a user in Organization Settings.
Configure your Encompass integration before enabling System Roles for your org.
Understand how conditions work in Inspect and which roles can create, edit, or waive them.
Learn how income calculations work in Analyze and which roles can view or edit values.
Updated 5 days ago