Role-based access control (RBAC)

RBAC lets your organization assign a defined persona to each Dashboard user so that capabilities in Analyze, Inspect, and Encompass import are gated by job function. Each user sees and can act on only what their role requires, giving lending teams least-privilege access by design, a clear auditable structure for compliance reviews, and a faster onboarding experience where new users are productive with the correct permissions from their first login.

System Roles is enabled per organization by your Ocrolus account manager. Contact your account manager to request enablement and to align on a duplicate-email resolution strategy before go-live.

RBAC offers the following capabilities:

Pre-built personas

Six roles that map to common lending-team structures. No configuration required to start.

Capability-level gates

Permissions control specific actions: edit income, create conditions, import to Encompass, and more.

Managed from one place

Admins assign and reassign roles right on the Team page in Organization Settings.

Safe by default

Restrict powerful actions to the roles that should have them, without blocking day-to-day work.

Key concepts

TermDefinition
System roleA pre-built permission profile assigned to a user. Each role bundles a specific set of capabilities across Analyze, Inspect, and Encompass import.
PermissionA specific action that a role can or cannot perform. For example, editing income values or importing conditions to Encompass.
Duplicate emailA conflict that occurs when an Encompass user's email address already exists in a different Ocrolus organization, requiring resolution before account linking completes.

System roles

RBAC offers six system roles, each reflecting a real seat on a lending team. Assign the role that matches each user's day-to-day responsibilities.

RolePrimary responsibilityAccess summary
Loan OfficerOriginates and sells loansViews income but cannot edit values or set conditions
ProcessorGathers and clears conditionsImports income, adds notes, uploads documents
UnderwriterMakes credit decisionsFull Inspect review; sets and waives conditions
Loan Officer (LO) / Processing AssistentSupports LOs and processorsRead-only or limited edit, depending on org configuration
Closer / FunderReviews the final loan packageMinimal access to Inspect and Analyze data
Lending Operations ManagerOversees the whole teamFull admin: configures access, audits usage

Role permission matrix

The table below shows the permissions granted per persona. View access is enabled by default for all personas. Only the actions listed below require explicit permission. Verify the exact configuration against your organization's live permissions before go-live.

CapabilityActionLoan OfficerProcessorUnderwriterLO / Processing Asst.Closer / FunderLending Ops Manager
Documents — index page + uploads
Delete forms from the document on index page
mortgage.book.form
DeleteNo accessNo accessNo accessNo accessNo accessGranted
Delete the uploaded doc from uploads section
mortgage.book.uploaded-doc
DeleteNo accessNo accessNo accessNo accessNo accessGranted
Delete the mixed document from uploads section
mortgage.book.mixed-uploaded-doc
DeleteNo accessNo accessNo accessNo accessNo accessGranted
Income — analyze / income screens + BSIC config
Edit income values on analyze / income screens or via API
mortgage.book.income
EditNo accessGrantedGrantedNo accessNo accessGranted
Edit book-level config for BSIC
mortgage.book.income.bsic
EditNo accessGrantedNo accessNo accessNo accessGranted
Edit org-level config for BSIC
mortgage.org.income.config
EditNo accessNo accessNo accessNo accessNo accessGranted
Comments — book level
Add book-level comments from the dashboard
book.comment
EditGrantedGrantedGrantedGrantedGrantedGranted
Delete book-level comments from the dashboard
book.comment
DeleteNo accessNo accessNo accessNo accessNo accessNo access
Conditions & Insights — inspect workflow
Create manual conditions on the Ocrolus dashboard
mortgage.book.inspect.condition
CreateNo accessGrantedGrantedNo accessGrantedGranted
Edit manual conditions on the Ocrolus dashboard
mortgage.book.inspect.condition
EditNo accessGrantedGrantedNo accessGrantedGranted
Resolve insights from the Ocrolus dashboard
mortgage.book.inspect.insight
EditNo accessGrantedGrantedNo accessGrantedGranted
Edit or confirm the mapped entity matching
mortgage.book.inspect.entity-matching.edit
EditNo accessGrantedGrantedNo accessNo accessGranted
Encompass / LOS Export — push from Ocrolus back to the LOS
Import income values back to Encompass
mortgage.los.book.income
EditNo accessGrantedGrantedNo accessNo accessGranted
Import insight values back to Encompass
mortgage.los.book.inspect.insight
EditGrantedGrantedGrantedGrantedGrantedGranted
Import conditions back to Encompass
mortgage.los.book.inspect.condition
EditGrantedGrantedGrantedGrantedGrantedGranted
Import the income worksheet back to eFolder in Encompass
mortgage.los.book.efolder.worksheet
EditNot specifiedGrantedGrantedNo accessNo accessGranted
Upload MISMO from the Inspect screen
mortgage.book.mismo.create
CreateGrantedGrantedGrantedGrantedNo accessGranted
Inspect Access — screen + tab visibility
View the Inspect screen
mortgage.inspect.view
ViewGrantedGrantedGrantedGrantedGrantedGranted
View the conditions tab on the Inspect screen
mortgage.book.inspect.condition.view
ViewGrantedGrantedGrantedGrantedGrantedGranted
Permissions granted6 of 1914 of 1913 of 196 of 198 of 1918 of 19
Granted: Permission is enabled for this persona.
No access: Hidden from the user's view entirely.
Not specified: Not defined in the source sheet.

  • Loan Officer income edit is namespaced mortgage.book.income; view access is granted to all users by default and only the edit action is controlled.

  • Source sheet lists Loan Officer document/comment keys without the mortgage. prefix and BSIC org config as mortgage.org.income.bsic — confirm the canonical namespace before implementation.

  • Processor condition edit covers both manual and automated conditions; all other personas cover manual conditions only.


Use cases

Each system role maps to a real workflow on the lending team. Here is how permissions play out in practice.

  • Loan officers get a clean and read-only income view. Review Analyze income data without any risk of editing calculated values or triggering actions reserved for underwriting.
  • Processors can import and annotate without touching conditions. Import income to Encompass, upload supporting documents, and add notes, without access to condition management, which stays restricted to underwriters.
  • Underwriters have full control over conditions. Set, edit, and waive conditions in Inspect and push them to Encompass. No other role has this level of access by default.
  • Lending Ops Managers onboard new users instantly. Assigning a persona takes one action in Organization Settings. A new user is productive with the correct permissions from their first login.
  • Access reviews and compliance audits are straightforward. Every user's effective permissions are visible in the Roles table at a glance, making periodic access reviews quick and auditable.

Known issues

The current release has a few boundaries worth knowing before you roll out. Most are already scoped for an upcoming phase.

LimitationDetail
No custom rolesOnly the six system personas are available. Org-specific permission sets are planned for a future phase.
No pre-login role assignmentA user profile is created on first login. Admins cannot pre-assign a role before that point.
Broad default on first loginFirst-login users receive a default role that grants broad access until an admin assigns a restricted role.
No admin-side Encompass user creationEncompass users are created by webhook or by logging in, not from the Ocrolus admin page.
No role-assignment remindersThere is no automated prompt to assign a role after a user's first login.

See also


Did this page help you?