Roles and Permissions

Modified on Wed, 15 Jul at 3:50 PM

Roles and Permissions

Default Roles and their Permissions

Default roles have been created to enable faster onboarding. Members who belong to default roles will be automatically added to all new wallets and enterprises in the organization with the respective permissions. The default roles have the following permissions across all wallets and enterprises. 

  • Organization Admin: a member managing user permissions and access

  • Enterprise Admin: a member creating wallets within the enterprise, managing enterprise-level policies

  • Wallet Admin: a member managing wallet-level policies and whitelist

  • Wallet Spender: a member initiating transactions

  • Wallet Trader: a member initiating trades, can also view all wallets in the enterprise

  • Video ID User: a member undergoing Video ID verification with BitGo’s Trust team, allowing them to authorize sensitive operations that require identity confirmation

  • Viewer: a member view wallet balances and transactions

  • Auditor: a member viewing activity logs

For more information about roles and permissions, please refer to the Roles and Permissions Matrix

Creating Custom Roles 

If you determine that custom roles need to be created for your organization, this can be done by the Organization Admins. Click Create Role at the bottom of the page. Once the custom role is created you can add members to it. This will require approval if your organization has more than one Organization Admin. 

  • Click on the Roles tab

  • Click on Create Role

  • Name the Role

  • Select the permissions that you want this role to have

  • Select the Enterprises that you want these permissions to apply to

    • All Enterprises: all enterprises that exist today and all future enterprises that are added the organization

    • Select Enterprises: if you only want this role to apply to certain enterprises

  • Choose to grant access to all wallets, or individually pick specific wallets for each enterprise:

    • All Wallets: all wallets that exist today and all future wallets that are added the enterprise

    • Select Wallets: if you only want certain wallets within the respective enterprise

When to Use Default vs. Custom Roles

Here are some things to consider when determining whether to leverage BitGo’s default roles for your organization or create custom roles: 

  • Do the default roles have the correct set of permissions? 

  • Should members in these roles have these permissions across enterprises and wallets, now and in the future? 

  • Are the default roles sufficient?

  • Does my organization require a unique combination of permissions and/or wallet and enterprise access?

Updating Roles

Only ONE update can be made to a role at a time. This update must be approved before other updates can be made to the same role. For example, if you want to add members, remove members and update permissions, you will only be able to do one after the other.

Note: 

  • Members must already exist to be added to a role in the Roles tab. If they are not in the Organization yet, they can be added from the Members tab. 

  • Every member must have at least one role to remain in an Organization.

Removing Members

Members can be removed from your organization on the Members tab of the Admin Console. Click Edit Member next to the member that you wish to remove then click Remove Member from Organization.

A note on self-custody wallets:

  • If you are removing a member who is the last key holder of a self-custody wallet, removing this user could freeze access to this wallet and funds could be lost. Ensure another member has key access to this wallet before proceeding. See Self-Custody Wallet Sharing for more information. 

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article