Help Centre

Platform Documentation

Role permissions, module access, regulatory basis, and how the platform works — for firm admins, compliance professionals, and regulated firms.

Role Overview

MandateAI has seven roles across two access layers — the compliance consultancy (your firm) and the regulated clients your firm manages.

Two-tier access model. Your firm's team members (Firm Admin, Supervisor, CO, MLRO) work across your client portfolio. Your clients' representatives access only their own data — either read-only (Client Portal) or with full workspace access (Client).
Role Who uses it Access scope MFA required
Admin MandateAI platform team only All firms, all clients, all data
Firm Admin Managing director / partner at your consultancy Team management + client onboarding portal. Does not access client compliance data directly.
Supervisor Senior consultant or QA reviewer Read + approve/attest across all clients assigned by Firm Admin
CO Compliance Officer assigned to a client Full read + write on all compliance modules for assigned clients
MLRO Money Laundering Reporting Officer assigned to a client Full read + write including STR/goAML submission and AML approval authority
Client Portal Regulated firm's own management or board View-only on their compliance workspace — no actions, no edits
Client Regulated firm's internal compliance contact Full compliance workspace for their firm only — isolated from all other clients
TOTP MFA is required for all roles with write access (CO, MLRO, Supervisor). Login sends a magic link; the first login for MFA-required roles prompts QR code setup.

Permissions by Role

What each role can and cannot do within the compliance dashboard.

Action Supervisor CO MLRO Client Portal Client
View compliance dashboard
Switch between clients
Create / edit tasks
Dispatch tasks to employees
Approve / attest tasks
Log breach / incident
Submit STR / goAML XML Prepare only
Run AML BRA / CDD
Run gap assessment / document audit View results
Upload evidence
Manage approved persons register
Sign declarations
File EPRS returns
Generate MI / board report View only
Configure notification settings
Use AI Compliance Assistant
Delete records
No role below Admin can permanently delete compliance records. This is intentional — ADGM/FSRA requires a minimum 6-year audit trail. Records can be closed, resolved, or superseded but not erased.

Module Access Matrix

Which platform modules each role can access.

Module Firm Admin Supervisor CO MLRO Client Portal Client
Team & Seat Management
Client Onboarding
AML Programme (BRA, CDD, Sanctions) View View
STR / goAML XML Builder Prepare ✓ Submit
Task Management & Approvals Approve only View
Breach & Incident Log View View
Approved Persons Register View View
Declarations & Attestations
EPRS Filing Calendar View View
Policy & Procedure Register View View
Document Auditor View
Gap Assessment View
MI Dashboard & Board Report
Regulatory Intelligence
AI Compliance Assistant
Employee Portal (self-service forms)
Notification Settings (Teams, WhatsApp, SMS)

ADGM Regulatory Basis

How MandateAI roles map to positions defined under the FSRA's regulatory framework.

The CO, MLRO, and Supervisor roles in MandateAI correspond directly to FSRA-mandated positions that every regulated firm must maintain under the FSRA Rulebook (COBS, AML Rules, and PRU). These are not optional titles — they carry personal regulatory accountability.
Platform role FSRA / ADGM equivalent Regulatory accountability
CO Compliance Officer (licensed individual) Personal accountability for the firm's compliance programme. Must hold FSRA approval as a Controlled Function (CF-4). Responsible for EPRS filings, annual compliance report, regulatory notifications.
MLRO Money Laundering Reporting Officer (licensed individual) Personal accountability for AML/CFT programme. Must hold FSRA approval as a Controlled Function (CF-3). Sole authority to submit STRs to the UAE FIU via goAML. Responsible for Business Risk Assessment and CDD oversight.
Supervisor Senior Manager / Compliance Oversight Board or senior management level oversight of the compliance programme. Reviews and approves CO/MLRO outputs. Not always a separately licensed individual — the role reflects the supervisory layer required under FSRA governance rules.
Client Regulated firm's internal compliance contact The firm's own staff who work within the compliance programme day-to-day. Not a licensed individual under FSRA — they work under the authority of the licensed CO/MLRO.
Client Portal Board / management visibility access No direct FSRA equivalent — a platform design role for giving a firm's senior management read-only visibility into the compliance programme without the ability to alter records.

A note on CO vs MLRO

In many smaller ADGM-regulated firms — particularly FinTechs and DNFBPs — one individual holds both the CO and MLRO licence. The platform supports this: a single person can be assigned the MLRO role and will have access to all CO and MLRO functions. The roles are kept separate in MandateAI to reflect firms where these are distinct licensed individuals, which is the more common structure in larger firms and compliance consultancies managing multiple clients.

Seats & Licensing

How the seat model works for compliance consultancies.

Concept How it works
Platform license Your firm pays an annual platform license (AED 75,000/year). This covers your team's access to the platform and the Firm Admin portal.
Included seats 8 team member seats are included in the base license. A seat is any team member you add — CO, MLRO, Supervisor, or additional Firm Admin.
Seat allocation You control how your 8 seats are allocated. There are no per-role seat limits — you can have 3 COs, 2 MLROs, 2 Supervisors, and 1 Firm Admin, or any other combination.
Client subscriptions Each regulated firm you onboard is a separate monthly subscription (AED 3,000/month per client). Client seats (Client and Client Portal roles) do not count against your team seat limit.
Overage If you need more than 8 team seats, contact us to add seats to your license. Your Firm Admin portal shows current usage vs. your limit at all times.
The Firm Admin role does not consume a billable team seat — it is included with your platform license and is always available to the designated account manager for your firm.

AML Programme Guide

Step-by-step guide to completing a Business Risk Assessment, CDD workflow, and preparing an STR for goAML submission. Coming soon.

Task Management Guide

How to create tasks, dispatch them to employees via magic-link email, collect responses, and route to approval. Coming soon.

EPRS Filing Calendar

How the EPRS filing calendar works, which return types are tracked, and how to log a submission. Coming soon.

goAML STR Submission

How MandateAI generates goAML-compliant XML for Suspicious Transaction Reports and how the MLRO submits them to the UAE FIU. Coming soon.