Contact Us

User Management: SinglePoint Role-Based Access Control

SinglePoint User Management gives the Company Administrator full control over every user inside the commercial relationship. Delegated provisioning, five role templates, per-account permissions, per-product permissions, dual-control thresholds and a 7-year audit log wrap every privileged action in an evidence trail aligned with OCC record-keeping expectations.

Initiator, Approver, Auditor, Administrator and Read-Only templates accelerate onboarding to minutes. Token assignment — hardware and software — is handled inside User Management with no phone call to U.S. Bank. Unlimited users, one unified access policy, one dashboard.

Sign In to SinglePoint Security Controls
SinglePoint User Management dashboard with role templates, permission matrix and dual-control thresholds

The Company Administrator Role

Every commercial relationship has at least two Company Administrators. The role carries the highest privilege inside SinglePoint User Management — the ability to create, modify and de-provision users.

Access Profile

  • Provisioning — create users, assign templates, grant per-account permissions.
  • Modification — edit roles, update dollar thresholds, rotate tokens.
  • De-Provisioning — disable users instantly upon termination.
  • Unlock — release locked accounts after failed sign-in attempts.
  • Audit Review — inspect the 7-year audit log with cryptographic manifest.

SinglePoint Role Templates

Five canonical roles, each clonable and customisable. Templates eliminate permission-by-permission configuration and standardise access patterns across the enterprise.

Initiator

Creates wires, ACH batches and bill payments. Cannot approve or release. Typical assignment — accounts payable clerks, payroll operators, treasury analysts. Per-account and per-product scoping restricts visibility to the accounts they service.

Approver

Reviews and approves initiated payments. Cannot create, cannot release without second approval above dual-control thresholds. Typical assignment — AP supervisors, treasury managers, line-of-business controllers.

Administrator

Full User Management authority — create, modify, de-provision users. Cannot initiate payments by default (separation of duties). Typical assignment — two named Company Administrators plus a delegated Deputy Administrator for continuity.

Auditor and Read-Only

Auditor sees every transaction, permission change and sign-in event — can export but cannot modify. Read-Only sees balances and transactions but cannot export or modify. Typical assignments — internal audit, external audit, CFO and executive observers.

Permission Matrix

The canonical permission matrix across the five SinglePoint role templates. Per-account and per-product scoping tighten these defaults further.

RoleInitiateApproveReleaseReports
InitiatorYesNoNoView only
ApproverNoYesWith dual-controlView and export
AdministratorNo (default)No (default)No (default)Full access
AuditorNoNoNoFull access + export
Read-OnlyNoNoNoView only

User Management by the Numbers

Unlimited users, five templates, 7-year audit retention.

5Canonical Role Templates
Delegated Users per Company
7 yrsAudit Log Retention
2Administrators Minimum

Dual-Control Thresholds and Token Assignment

Dual-Control Configuration

The Company Administrator configures dollar thresholds per product. Wires over $50,000 commonly require a second named approver. ACH batches over $250,000 commonly require a second approver. Thresholds can be tighter for unfamiliar beneficiaries, international destinations or after-hours submissions. SinglePoint enforces the configured thresholds without exception — no override, no emergency bypass.

SinglePoint dual-control threshold configuration panel for wires and ACH
Hardware and software token assignment in SinglePoint User Management

Token Assignment

Hardware tokens and the U.S. Bank Token app are assigned from inside User Management. Hardware tokens ship by trackable courier; software tokens activate via enrolment code. Token rotation, replacement and decommissioning all flow through the same User Management workspace with audit trail.

Per OCC guidance on authentication for online banking, SinglePoint layers MFA, device binding and geo-pattern detection behind every privileged session.

Audit Log Retention

Every User Management event is logged for 7 years with cryptographic manifest. Provisioning, de-provisioning, permission change, dual-control approval, token assignment, unlock — each captured with timestamp, IP address, device fingerprint and before/after field state. The audit export is admissible for SOX Section 404, SOC 1/2 and internal audit review.

SinglePoint audit log export with cryptographic manifest and 7-year retention

People Also Ask

Who is the SinglePoint Company Administrator?
The named commercial client user responsible for provisioning, modifying and de-provisioning SinglePoint users. Every relationship has at least two Company Administrators for continuity.
What role templates ship out of the box?
Initiator, Approver, Auditor, Administrator and Read-Only. Each is clonable and customisable per account, per product and per dollar threshold.
How do dual-control thresholds work?
Configured per product by the Company Administrator. Wires over $50,000 commonly require a second approver; ACH over $250,000 commonly requires dual control. SinglePoint enforces without exception.
How long is the audit log retained?
7 years, in alignment with OCC record-keeping expectations — covering provisioning, permission changes, dual-control approvals and sign-in attempts.
Can users be restricted to specific accounts?
Yes. Per-account permissions enforce at the API and UI layer so restricted accounts never appear in dropdowns, reports or search.

Commercial Banking Portal — Topic Cluster