MMashDiv

Who can do what - delegating the Convert console

How the install grants the Convert keys from keys your roles already hold, why the three manage keys are granted to nobody, which keys let a delegate move the house's money or decide what happened on a chain, and the role layout that keeps those apart.

2 min readUpdated 28 September 2026admin, permissions, roles, delegation, super-admin

Instant Convert follows the platform's <verb>.convert.<section> pattern: access opens a screen, view reads it, edit changes terms or moves the house's inventory, and manage settles something only a person can decide. Every key and the route or screen that demands it is in the permissions reference.

What the install grants

The permission seeder that ships with Instant Convert derives grants from keys you already chose by hand, never from a role's name, so an install that renamed or split its roles is not silently left out:

Keys Granted to every role that holds
access.convert, view.convert, every view.convert.*, access.convert.settings view.transaction
every edit.convert.* both edit.deposit and edit.withdraw
manage.convert.send, manage.convert.hedge, manage.convert.rebalance nobody
  • Read follows view.transaction. Every Convert screen reads customer converts and the house's balances: the same ledger the transaction log shows, seen from the other side.
  • Edit needs both money witnesses. Enabling an asset, funding or defunding the house, setting floors and caps, changing the fee and spread and starting a house movement each move or price the platform's own inventory against customer money. A role that already decides customer money in both directions holds more than this; a role that decides only one does not acquire the other sideways through a console it has never seen.
  • Manage is granted to nobody. Approving, confirming or reversing a Send, resolving a hedge or a movement in review, and unfreezing a currency each declare, on the operator's word, what happened on a chain or at a venue, and a wrong answer pays twice or not at all. No existing key has that weight to derive from.

The seeder only adds missing pairs. It never revokes, never widens a role beyond what its witnesses already say, and running it again changes nothing. Super Admin holds everything by name and needs no rows.

Keys that can cost money in the wrong hands

Key Why it matters
manage.convert.send Reversing a payout that later lands pays the user twice from the house. The engine demands the chain's proof, but approve and confirm are still judgements.
manage.convert.hedge Marking a hedge failed that did execute leaves a position unbooked and hedged twice. Unfreezing and reopening quoting put a currency back in play.
manage.convert.rebalance Marking a movement failed, or writing a credit off, decides where the house's coins are.
edit.convert.inventory Funds and defunds the house from the Super Admin wallet, sets each currency's floor and target (a lower floor lets the house pay out further), and turns Convert & Send on or off per chain, with the house's on-chain floor and target there.
edit.convert.settings The fee, the spread, the guards and the limits. Also runs Sweep now on the P&L page. The nine protected keys still need a Super Admin.
edit.convert.asset Opens a currency to converts, or widens its size limits.
edit.convert.rebalance Starts a house movement by hand: the house's own coins leave the exchange for a chain, or a chain for the exchange. Every switch, band floor and venue limit of the automatic cycle still applies.
manage.pool.backing The core Instant Convert house page: defund, and settle Sends, hedges and movements while the addon is off. Always with a second factor; the kill switches also need Super Admin.

A layout that keeps them apart

  • Support reads: access.convert, view.convert*. They can see a user's convert, its quote and its payout, and answer the ticket.
  • Treasury funds, prices and moves the house's coins: add edit.convert.asset, edit.convert.inventory, edit.convert.rebalance and edit.convert.settings.
  • Operations settles the queues: add manage.convert.send, manage.convert.hedge and manage.convert.rebalance, to the few people who will actually check an explorer or a venue before they click.
  • Super Admin keeps the kill switches, the exposure and hedge caps, drain mode and the profit sweep.

Alerts about stuck payouts go only to accounts whose role is named Admin or Super Admin (Super Admin alone on a demo install): an Admin who holds view.convert.send or manage.convert.send, and every Super Admin. The install gives view.convert.send to every role that holds view.transaction, so such an Admin role is alerted without further grants. A role you create, such as the Operations role above, is never alerted whatever keys it holds, so whoever settles the queues there should watch Sends and the dashboard's Needs attention card.