Set up users and roles

Overview

Your admin account has both Merchant Admin and Merchant Supervisor access, which provides access to all features of the OnlinePay dashboard. You can create additional user accounts and assign roles to them when you log in using this account.

⚠️

Important

You, the merchant, are responsible for the administration and establishment of user accounts and their appropriate access levels. You can set up as many user accounts as required. Users can have multiple roles. User accounts are established using an email address, which must be unique.

We recommend ensuring that you delete any user accounts that are no longer required. We have included some information here to help you choose your roles.

Users with Merchant Admin permission can create and manage users in the dashboard via Administration > Account Setup > Users.

Create a new user

Merchant Admin users can create new users in the dashboard. To create a new user, follow these steps:

  1. Log in to the dashboard.

  2. Navigate to Administration > Account Setup > Users.

  3. Click Add new user.

  4. Complete the user details form :

  5. Click Save.

The new user details screen shows the user's details, including the user's role and status. From here you can edit the user's details, or disable the user account.

Merchant roles

Merchant Admin

This Administrative role is required to establish settings to get you started, including setting up and managing users, blocking rules, and notification services.

Merchant Admin users can create and manage users (including resetting user passwords) in the dashboard by navigating to Administration > Account Setup > Users.

SectionComponents and features (subsection)Permissions
Administration — Merchant Account Configuration and OnboardingOrganisationsRead
Secure Card CaptureYes
Token ScopeYes
Payment Provider ContractsRead
Point of InteractionRead
3D Secure ContractsRead
WalletsCreate, Read, Disable
UsersCreate, Read, Update, Delete, Self read, Self update, Reset password, Create API key
Blocking RulesetsCreate, Read, Update, Delete
Notification ServiceCreate, Read, Update, Disable
Audit LogRead
Reporting and AnalyticsOrders/Transactions ReportsAccess, View, Transaction details, Export CSV, Access receipts
SettlementsRead
3D Secure AuthenticationsAccess, View
Report SchedulerView
Generated ReportsView

Merchant Supervisor

This user can use all payment tools (e.g., Virtual Terminal, Payment Links) and perform all payment actions (including refunds).

SectionComponents and features (subsection)Permissions
Administration — Merchant Account Configuration and OnboardingOrganisationsRead
Payment Provider ContractsRead
Point of InteractionRead
3D Secure ContractsRead
WalletsCreate, Read
UsersRead, Self read, Self update, Create API key
Blocking RulesetsRead
Notification ServiceCreate, Read, Update, Disable
Checkout ThemesCreate, View, Read, Update, Delete
Payment ToolsVirtual TerminalAccess, View, Create and initiate payment, Void payment, Capture payment, Refund, Cancel
Pay by LinkAccess, View PBL list, Create link, Re-enable link, Disable link
Reporting and AnalyticsOrders/Transactions ReportsAccess, View, Transaction details, Export CSV, Refund, Capture, Void, Access receipts, Void capture
SettlementsRead
3D Secure AuthenticationsAccess, View
Report SchedulerView
Generated ReportsView

Merchant Cashier

This role can access all payment tools but cannot process refunds.

SectionComponents and features (subsection)Permissions
Administration — Merchant Account Configuration and OnboardingOrganisationsRead
Point of InteractionRead
UsersSelf read, Self update, Create API key
Checkout ThemesCreate, View, Read, Update, Delete
Payment ToolsVirtual TerminalAccess, View, Create and initiate payment, Void payment
Pay by LinkAccess, View PBL list, Create link, Re-enable link, Disable link
Reporting and AnalyticsOrders/Transactions ReportsAccess, View, Transaction details, Export CSV, Void, Access receipts
3D Secure AuthenticationsAccess, View

Merchant Reviewer

The Merchant Reviewer role is a read-only access role that grants users viewing permissions across the dashboard but without the ability to perform any actions. This role is suitable for users in junior finance or technical roles who need to view the number of transactions, settlements, and authentications, but are not required to generate reports.

SectionComponents and features (subsection)Permissions
Administration — Merchant Account Configuration and OnboardingOrganisationsRead
Payment Provider ContractsRead
Point of InteractionRead
3D Secure ContractsRead
WalletsRead
UsersRead, Self read
Blocking RulesetsRead
Reporting and AnalyticsOrders/ Transactions ReportsAccess, View, Transaction details, Export CSV
SettlementsRead
3D Secure AuthenticationsAccess, View

Merchant User

This role provides read-only access to the dashboard, with the ability to run and export reports. Merchant users can view transactions but are prevented from performing actions. They can view payments, settlements, and reports, and may be a suitable role for a user in a finance or accounting role.

SectionComponents and features (subsection)Permissions
Administration — Merchant Account Configuration and OnboardingOrganisationsRead
Payment Provider ContractsRead
Point of InteractionRead
3D Secure ContractsRead
WalletsRead
UsersSelf read, Self update
Blocking RulesetsRead
Reporting and AnalyticsOrders/Transactions ReportsAccess, View, Transaction details, Export CSV
SettlementsRead
3D Secure AuthenticationsAccess, View (Only for their organisation. Merchant Users cannot access the 3D Secure Authentications of their sub-organisations.)
Report SchedulerView
Generated ReportsView

Merchant External Partner

This role grants access to a user outside of of the merchant company, for example, a web developer or other non-financial role, such as logistics. These users are trusted with access to order and transaction data, but are restricted from performing any payment actions.

SectionComponents and features (subsection)Permissions
Administration — Merchant Account Configuration and OnboardingUsersCreate, Self read, Self update
Reporting and AnalyticsOrders/Transactions ReportsAccess, View

Example role assignment scenarios

The following example scenarios may help you to understand which roles to assign to users in your organisation.

Sole Traders

An admin account is set up with Merchant Admin and Merchant Supervisor, which may suit the sole trader, as all features can be accessed under these roles. The sole trader could also grant another person (for example, an accountant) access to a Merchant User role, which provides read access to transactions only.

A small company with fewer than five employees

An admin account is set up with Merchant Admin and Merchant Supervisor roles, with all features accessible to these roles. The Merchant Admin user may choose to provide Merchant Cashier role to staff members who can view transactions and run reports but restrict refund processing to management under the Merchant Supervisor role.

A web developer you have hired to build your new online store

You have contracted a web developer to build your new online store. You can provide them with a Merchant External Partner` role, which allows them to access the dashboard to view information to confirm that their integration is working correctly, but they cannot perform any payment actions.

Disable a user account

You can disable a user account if the user no longer requires access to the dashboard. To disable a user account, follow these steps:

  1. Log in to the dashboard.

  2. Navigate to Administration > Account Setup > Users.

  3. Click the name of the user that you want to disable from the list, or use the search function to find the user, then click their name.

  4. Click Disable user.

  5. The confirmation screen advises that disabling the user account means they will no longer be able to log in to the dashboard. Click Disable user to confirm, or Keep user enabled if you do not want to remove their access.

You can re-enable a user account at any time by clicking Enable user on the user details screen of a user account that has been disabled.

Delete a user account

You can delete a user account that has been disabled if you no longer require the user account. This will permanently delete their account.

  1. In the OnlinePay dashboard, navigate to Administration > Account Setup > Users.

  2. Click the name of the user that you want to delete from the list, or use the search function to find the user, then click their name.

    ℹ️

    Note

    You can only delete a user account that has been disabled. If you want to delete an active user account, you must first disable the account. See Disable a user account for more information.

  3. Click Delete user.

  4. The confirmation screen advises that deleting the user account will permanently remove the user from the dashboard.

    Select a reason for deleting the user from the available options:

    • This user is no longer required.
    • Wrong email address has been added.
    • Others

    When you have selected a reason, click Delete user to confirm, or Keep user if you do not want to delete the user account.

The user account is permanently deleted and no longer appears in the list of users in the dashboard.



St. George BankSA Bank of Melbourne

This information is a general statement for information purposes only and should only be used as a guide. While all care has been taken in preparation of this document, no member of the Westpac Group, nor any of their employees or directors gives any warranty of accuracy or reliability nor accepts any liability in any other way, including by reason of negligence for any errors or omissions contained herein, to the extent permitted by law. Unless otherwise specified, the products and services described are available only in Australia.

© St.George, Bank of Melbourne and BankSA – Divisions of Westpac Banking Corporation ABN 33 007 457 141 AFSL and Australian credit licence 233714.