Team & roles
In brief: Invite users, set roles, appoint your MLRO.
Watch this in the product
All tutorialsAdding colleagues, and what happens when they leave
Invites, what the roles genuinely differ on, and why removal never erases the record.
How to invite colleagues to your firm workspace and what each role can do. The role you pick determines what a user sees, what they can change, and whether they count as the firm's MLRO for audit purposes.
Where to find it
Sidebar → Settings → Team, or the standalone Team page if you've enabled the legacy view.
Roles
| Role | Can do |
|---|---|
| Owner | Everything. Billing, branding, deleting the firm. |
| Manager | Day-to-day admin: invite team, edit settings, action MLRO queue. Can be appointed MLRO / Deputy MLRO. |
| Compliance officer | Action MLRO queue items, run AML screens, sign off cases. Cannot edit billing. |
| Staff | Operate on client files (upload docs, request verification), view dashboards. Cannot edit settings. |
| Auditor | Read-only across the entire firm. Useful for external auditors and inspections. |
A user has exactly one role per firm. To change it, click their row → Change role.
Inviting someone
Invite member → email + role. They get an invite link valid for 7
days. When they accept they hit /auth/accept-invite?token=…, set a
password, and land on your firm's dashboard.
Invites are tied to email. If the person already has a Certivus account with that address, the invite page asks them to sign in with their existing password (not a new one); they then come straight back to the invite and join your firm. If they use two-factor authentication, they enter their code first.
Appointing the MLRO
MLR 2017 reg 21 requires you to nominate an MLRO and (for larger firms) a Deputy. Use Settings → AML Compliance → MLRO appointments to record who currently holds each role. The active appointment shows on the compliance pack, the annual MLRO report, and the firm-wide audit log.
The MLRO must be a registered user in your firm; they don't have to be the owner.
Removing access
Remove from firm revokes the user's access immediately and logs the event in the audit log. Their historical actions (signed-off cases, audit log entries) stay attributed to them; you're auditing what they did, not whether they still work for you.
Related
- First-run wizard: initial team setup
- Audit log: every team/role change is recorded
Didn't find what you needed?
Contact support