Merchant roles and permissions

Overview

OnlinePay includes a number of roles with associated permissions that can be assigned to users in your organisation. These roles are designed to help you manage your payments and transactions, and to ensure that users have the appropriate level of access to the dashboard, or are restricted from performing certain actions.

Merchant roles

Merchant Admin

This Administrative role is required to establish settings to get you started, including setting up and managing users, blocking rules, and notification services.

Merchant Admin users can create and manage users (including resetting user passwords) in the dashboard by navigating to Administration > Account Setup > Users.

SectionComponents and features (subsection)Permissions
Administration — Merchant Account Configuration and OnboardingOrganisationsRead
Secure Card CaptureYes
Token ScopeYes
Payment Provider ContractsRead
Point of InteractionRead
3D Secure ContractsRead
WalletsCreate, Read, Disable
UsersCreate, Read, Update, Delete, Self read, Self update, Reset password, Create API key
Blocking RulesetsCreate, Read, Update, Delete
Notification ServiceCreate, Read, Update, Disable
Audit LogRead
Reporting and AnalyticsOrders/Transactions ReportsAccess, View, Transaction details, Export CSV, Access receipts
SettlementsRead
3D Secure AuthenticationsAccess, View
Report SchedulerView
Generated ReportsView

Merchant Supervisor

This user can use all payment tools (e.g., Virtual Terminal, Payment Links) and perform all payment actions (including refunds).

SectionComponents and features (subsection)Permissions
Administration — Merchant Account Configuration and OnboardingOrganisationsRead
Payment Provider ContractsRead
Point of InteractionRead
3D Secure ContractsRead
WalletsCreate, Read
UsersRead, Self read, Self update, Create API key
Blocking RulesetsRead
Notification ServiceCreate, Read, Update, Disable
Checkout ThemesCreate, View, Read, Update, Delete
Payment ToolsVirtual TerminalAccess, View, Create and initiate payment, Void payment, Capture payment, Refund, Cancel
Pay by LinkAccess, View PBL list, Create link, Re-enable link, Disable link
Reporting and AnalyticsOrders/Transactions ReportsAccess, View, Transaction details, Export CSV, Refund, Capture, Void, Access receipts, Void capture
SettlementsRead
3D Secure AuthenticationsAccess, View
Report SchedulerView
Generated ReportsView

Merchant Cashier

This role can access all payment tools but cannot process refunds.

SectionComponents and features (subsection)Permissions
Administration — Merchant Account Configuration and OnboardingOrganisationsRead
Point of InteractionRead
UsersSelf read, Self update, Create API key
Checkout ThemesCreate, View, Read, Update, Delete
Payment ToolsVirtual TerminalAccess, View, Create and initiate payment, Void payment
Pay by LinkAccess, View PBL list, Create link, Re-enable link, Disable link
Reporting and AnalyticsOrders/Transactions ReportsAccess, View, Transaction details, Export CSV, Void, Access receipts
3D Secure AuthenticationsAccess, View

Merchant Reviewer

The Merchant Reviewer role is a read-only access role that grants users viewing permissions across the dashboard but without the ability to perform any actions. This role is suitable for users in junior finance or technical roles who need to view the number of transactions, settlements, and authentications, but are not required to generate reports.

SectionComponents and features (subsection)Permissions
Administration — Merchant Account Configuration and OnboardingOrganisationsRead
Payment Provider ContractsRead
Point of InteractionRead
3D Secure ContractsRead
WalletsRead
UsersRead, Self read
Blocking RulesetsRead
Reporting and AnalyticsOrders/ Transactions ReportsAccess, View, Transaction details, Export CSV
SettlementsRead
3D Secure AuthenticationsAccess, View

Merchant User

This role provides read-only access to the dashboard, with the ability to run and export reports. Merchant users can view transactions but are prevented from performing actions. They can view payments, settlements, and reports, and may be a suitable role for a user in a finance or accounting role.

SectionComponents and features (subsection)Permissions
Administration — Merchant Account Configuration and OnboardingOrganisationsRead
Payment Provider ContractsRead
Point of InteractionRead
3D Secure ContractsRead
WalletsRead
UsersSelf read, Self update
Blocking RulesetsRead
Reporting and AnalyticsOrders/Transactions ReportsAccess, View, Transaction details, Export CSV
SettlementsRead
3D Secure AuthenticationsAccess, View (Only for their organisation. Merchant Users cannot access the 3D Secure Authentications of their sub-organisations.)
Report SchedulerView
Generated ReportsView

Merchant External Partner

This role grants access to a user outside of of the merchant company, for example, a web developer or other non-financial role, such as logistics. These users are trusted with access to order and transaction data, but are restricted from performing any payment actions.

SectionComponents and features (subsection)Permissions
Administration — Merchant Account Configuration and OnboardingUsersCreate, Self read, Self update
Reporting and AnalyticsOrders/Transactions ReportsAccess, View

Example role assignment scenarios

The following example scenarios may help you to understand which roles to assign to users in your organisation.

Sole Traders

An admin account is set up with Merchant Admin and Merchant Supervisor, which may suit the sole trader, as all features can be accessed under these roles. The sole trader could also grant another person (for example, an accountant) access to a Merchant User role, which provides read access to transactions only.

A small company with fewer than five employees

An admin account is set up with Merchant Admin and Merchant Supervisor roles, with all features accessible to these roles. The Merchant Admin user may choose to provide Merchant Cashier role to staff members who can view transactions and run reports but restrict refund processing to management under the Merchant Supervisor role.

A web developer you have hired to build your new online store

You have contracted a web developer to build your new online store. You can provide them with a Merchant External Partner` role, which allows them to access the dashboard to view information to confirm that their integration is working correctly, but they cannot perform any payment actions.



St. George BankSA Bank of Melbourne

This information is a general statement for information purposes only and should only be used as a guide. While all care has been taken in preparation of this document, no member of the Westpac Group, nor any of their employees or directors gives any warranty of accuracy or reliability nor accepts any liability in any other way, including by reason of negligence for any errors or omissions contained herein, to the extent permitted by law. Unless otherwise specified, the products and services described are available only in Australia.

© St.George, Bank of Melbourne and BankSA – Divisions of Westpac Banking Corporation ABN 33 007 457 141 AFSL and Australian credit licence 233714.