{"templateId":"markdown","versions":[{"version":"v1.40","label":"v1.40 STS","link":"/products/custody/governance/users/examples","default":true,"active":true,"folderId":"c15a2701"},{"version":"v1.39","label":"v1.39 STS","link":"/products/custody/v1.39/governance/users/examples","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.38","label":"v1.38 STS","link":"/products/custody/v1.38/governance/users/examples","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.34","label":"v1.34 LTS","link":"/products/custody/v1.34/governance/users/examples","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.26","label":"v1.26 LTS","link":"/products/custody/v1.26/governance/users/examples","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.19","label":"v1.19 LTS","link":"/products/custody/v1.19/governance/users/examples","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.15","label":"v1.15 LTS","link":"/products/custody/v1.15/governance/users/examples","default":false,"active":false,"folderId":"c15a2701"}],"sharedDataIds":{"sidebar":"sidebar-products/custody/@v1.15/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"User and role examples","description":"User guides, API reference, and support resources.","siteUrl":"https://docs.ripple.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"user-and-role-examples","__idx":0},"children":["User and role examples"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use these examples as starting points for role design. Adapt role names to your operating model, then use the same names in users, policies, and read access."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Roles are role-name strings that you can define whenever you need them. In the standard governed user-management flow, assigning a role to a user or changing a user's roles requires an approved ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_CreateUser"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UpdateUser"]}," intent."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"role-catalog","__idx":1},"children":["Role catalog"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Role"},"children":["Role"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Common use"},"children":["Common use"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["platform-admin"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Human"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Root-domain administration and emergency governance."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["domain-admin"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Human"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Domain administration for a specific domain or domain family."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["policy-operator"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Human"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Policy creation and policy changes."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["transaction-operator"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Human"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Routine transfer or transaction creation."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["transaction-operator-bot"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Bot user"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Automated transaction creation under controlled policies."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["compliance"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Human"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Screening, quarantine release, and exception review."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["auditor"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Human"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Read-only review of requests, events, policies, and transactions."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["emergency-operator"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Human"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Breakglass or recovery approval."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"minimal-launch-model","__idx":2},"children":["Minimal launch model"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use this only for small launch environments where duties are simple but quorum is still required."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Role"},"children":["Role"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Minimum users"},"children":["Minimum users"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Purpose"},"children":["Purpose"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["platform-admin"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Root administration and recovery."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["policy-operator"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Policy changes."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["transaction-operator"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Routine transaction operations."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["compliance"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["1 or 2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Compliance review, if used at launch."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Policy implication: do not require a quorum that this user model cannot satisfy."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"segregated-operating-model","__idx":3},"children":["Segregated operating model"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use this when administration, policy management, operations, and compliance are separate teams."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Role"},"children":["Role"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Minimum users"},"children":["Minimum users"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Typical workflows"},"children":["Typical workflows"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["platform-admin"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Domain and emergency operations."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["user-admin"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["User creation, user role-assignment changes, lock and unlock."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["policy-operator"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Policy create, update, lock, unlock."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["transaction-operator"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["2 or more"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Transfer creation."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["compliance"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Quarantine and exception approval."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["auditor"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["As needed"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Read-only review."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Policy implication: role elevation and policy changes should require stronger approval than routine operations."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"automation-model","__idx":4},"children":["Automation model"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use bot users for automated workflows such as scheduled transfers or integration with external systems."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Use case"},"children":["Use case"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Intent types"},"children":["Intent types"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Additional restrictions"},"children":["Additional restrictions"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Gas Station"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_CreateTransactionOrder"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Native token transfers only, specific source accounts."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Scheduled transfers"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_CreateTransactionOrder"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Specific source/destination accounts."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Account management"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_CreateAccount"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Specific domains."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Policy implication: for fully automated operation, create policies that allow automatic approval of the bot user's transactions. Without auto-approval, transactions created by the bot user queue for manual approval."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"emergency-model","__idx":5},"children":["Emergency model"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Emergency roles should be independent from routine operators where possible."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Role"},"children":["Role"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Purpose"},"children":["Purpose"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["emergency-operator"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Approves breakglass or recovery workflows."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["platform-admin"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Coordinates root-domain recovery."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["compliance"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Reviews regulatory or legal emergency actions."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Policy implication: emergency workflows should be explicit, high quorum, and scoped to the emergency intent types they are meant to govern."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For planning guidance, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/genesis/plan-your-first-users"},"children":["Plan your first users"]},". For fields and naming guidance, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/users/reference"},"children":["User and role reference"]},"."]}]},"headings":[{"value":"User and role examples","id":"user-and-role-examples","depth":1},{"value":"Role catalog","id":"role-catalog","depth":2},{"value":"Minimal launch model","id":"minimal-launch-model","depth":2},{"value":"Segregated operating model","id":"segregated-operating-model","depth":2},{"value":"Automation model","id":"automation-model","depth":2},{"value":"Emergency model","id":"emergency-model","depth":2}],"frontmatter":{"seo":{"title":"User and role examples"}},"lastModified":"2026-08-05T09:55:07.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/custody/governance/users/examples","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}