> ## Documentation Index
> Fetch the complete documentation index at: https://docs.finpace.tech/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and governance

> Security, role controls, approvals, encryption, and audit expectations.

# Security and governance

## Core control domains

The platform supports:

* role-based access control
* fine-grained entitlements by action and object
* maker-checker approval rules
* segregation of duties validation
* full audit history for configuration and servicing changes
* encryption in transit and at rest
* credential isolation for partner integrations
* document and consent evidence retention

## Role domains

### Front-office roles

* relationship manager
* branch operator
* contact-center operator
* assisted-onboarding operator

### Middle-office roles

* underwriting analyst
* risk officer
* compliance reviewer
* operations controller

### Back-office roles

* payments operator
* finance and reconciliation analyst
* product administrator
* data maintenance administrator
* system administrator

### AI runtime roles

* policy administrator
* tool publisher
* audit reviewer
* runtime operator

## Protected actions

The following actions default to protected status:

* arrangement closure
* signatory or mandate changes
* entitlement changes
* limit increases
* payment override approvals
* liquidity sweep policy changes
* credit decisions
* drawdown approval
* covenant breach waivers
* collateral release
* product parameter changes
* experiment publication
* AI tool publication and policy changes

## Audit model

Every protected action preserves:

* who requested it
* on whose behalf it was requested
* which policy pack was evaluated
* whether approval was required
* who approved it
* what state changed
* which objects were affected
* the final outcome
