Role Overview
MandateAI has seven roles across two access layers — the compliance consultancy (your firm) and the regulated clients your firm manages.
| Role | Who uses it | Access scope | MFA required |
|---|---|---|---|
| Admin | MandateAI platform team only | All firms, all clients, all data | ✓ |
| Firm Admin | Managing director / partner at your consultancy | Team management + client onboarding portal. Does not access client compliance data directly. | — |
| Supervisor | Senior consultant or QA reviewer | Read + approve/attest across all clients assigned by Firm Admin | ✓ |
| CO | Compliance Officer assigned to a client | Full read + write on all compliance modules for assigned clients | ✓ |
| MLRO | Money Laundering Reporting Officer assigned to a client | Full read + write including STR/goAML submission and AML approval authority | ✓ |
| Client Portal | Regulated firm's own management or board | View-only on their compliance workspace — no actions, no edits | — |
| Client | Regulated firm's internal compliance contact | Full compliance workspace for their firm only — isolated from all other clients | — |
Permissions by Role
What each role can and cannot do within the compliance dashboard.
| Action | Supervisor | CO | MLRO | Client Portal | Client |
|---|---|---|---|---|---|
| View compliance dashboard | ✓ | ✓ | ✓ | ✓ | ✓ |
| Switch between clients | ✓ | ✓ | ✓ | — | — |
| Create / edit tasks | — | ✓ | ✓ | — | ✓ |
| Dispatch tasks to employees | — | ✓ | ✓ | — | ✓ |
| Approve / attest tasks | ✓ | — | ✓ | — | — |
| Log breach / incident | — | ✓ | ✓ | — | ✓ |
| Submit STR / goAML XML | — | Prepare only | ✓ | — | — |
| Run AML BRA / CDD | — | ✓ | ✓ | — | ✓ |
| Run gap assessment / document audit | View results | ✓ | ✓ | — | ✓ |
| Upload evidence | — | ✓ | ✓ | — | ✓ |
| Manage approved persons register | — | ✓ | ✓ | — | ✓ |
| Sign declarations | ✓ | ✓ | ✓ | — | ✓ |
| File EPRS returns | — | ✓ | ✓ | — | ✓ |
| Generate MI / board report | ✓ | ✓ | ✓ | View only | ✓ |
| Configure notification settings | — | ✓ | ✓ | — | ✓ |
| Use AI Compliance Assistant | ✓ | ✓ | ✓ | — | ✓ |
| Delete records | — | — | — | — | — |
Module Access Matrix
Which platform modules each role can access.
| Module | Firm Admin | Supervisor | CO | MLRO | Client Portal | Client |
|---|---|---|---|---|---|---|
| Team & Seat Management | ✓ | — | — | — | — | — |
| Client Onboarding | ✓ | — | — | — | — | — |
| AML Programme (BRA, CDD, Sanctions) | — | View | ✓ | ✓ | View | ✓ |
| STR / goAML XML Builder | — | — | Prepare | ✓ Submit | — | — |
| Task Management & Approvals | — | Approve only | ✓ | ✓ | View | ✓ |
| Breach & Incident Log | — | View | ✓ | ✓ | View | ✓ |
| Approved Persons Register | — | View | ✓ | ✓ | View | ✓ |
| Declarations & Attestations | — | ✓ | ✓ | ✓ | — | ✓ |
| EPRS Filing Calendar | — | View | ✓ | ✓ | View | ✓ |
| Policy & Procedure Register | — | View | ✓ | ✓ | View | ✓ |
| Document Auditor | — | View | ✓ | ✓ | — | ✓ |
| Gap Assessment | — | View | ✓ | ✓ | — | ✓ |
| MI Dashboard & Board Report | — | ✓ | ✓ | ✓ | ✓ | ✓ |
| Regulatory Intelligence | — | ✓ | ✓ | ✓ | — | ✓ |
| AI Compliance Assistant | — | ✓ | ✓ | ✓ | — | ✓ |
| Employee Portal (self-service forms) | — | — | ✓ | ✓ | — | ✓ |
| Notification Settings (Teams, WhatsApp, SMS) | — | — | ✓ | ✓ | — | ✓ |
ADGM Regulatory Basis
How MandateAI roles map to positions defined under the FSRA's regulatory framework.
| Platform role | FSRA / ADGM equivalent | Regulatory accountability |
|---|---|---|
| CO | Compliance Officer (licensed individual) | Personal accountability for the firm's compliance programme. Must hold FSRA approval as a Controlled Function (CF-4). Responsible for EPRS filings, annual compliance report, regulatory notifications. |
| MLRO | Money Laundering Reporting Officer (licensed individual) | Personal accountability for AML/CFT programme. Must hold FSRA approval as a Controlled Function (CF-3). Sole authority to submit STRs to the UAE FIU via goAML. Responsible for Business Risk Assessment and CDD oversight. |
| Supervisor | Senior Manager / Compliance Oversight | Board or senior management level oversight of the compliance programme. Reviews and approves CO/MLRO outputs. Not always a separately licensed individual — the role reflects the supervisory layer required under FSRA governance rules. |
| Client | Regulated firm's internal compliance contact | The firm's own staff who work within the compliance programme day-to-day. Not a licensed individual under FSRA — they work under the authority of the licensed CO/MLRO. |
| Client Portal | Board / management visibility access | No direct FSRA equivalent — a platform design role for giving a firm's senior management read-only visibility into the compliance programme without the ability to alter records. |
A note on CO vs MLRO
In many smaller ADGM-regulated firms — particularly FinTechs and DNFBPs — one individual holds both the CO and MLRO licence. The platform supports this: a single person can be assigned the MLRO role and will have access to all CO and MLRO functions. The roles are kept separate in MandateAI to reflect firms where these are distinct licensed individuals, which is the more common structure in larger firms and compliance consultancies managing multiple clients.
Seats & Licensing
How the seat model works for compliance consultancies.
| Concept | How it works |
|---|---|
| Platform license | Your firm pays an annual platform license (AED 75,000/year). This covers your team's access to the platform and the Firm Admin portal. |
| Included seats | 8 team member seats are included in the base license. A seat is any team member you add — CO, MLRO, Supervisor, or additional Firm Admin. |
| Seat allocation | You control how your 8 seats are allocated. There are no per-role seat limits — you can have 3 COs, 2 MLROs, 2 Supervisors, and 1 Firm Admin, or any other combination. |
| Client subscriptions | Each regulated firm you onboard is a separate monthly subscription (AED 3,000/month per client). Client seats (Client and Client Portal roles) do not count against your team seat limit. |
| Overage | If you need more than 8 team seats, contact us to add seats to your license. Your Firm Admin portal shows current usage vs. your limit at all times. |
AML Programme Guide
Step-by-step guide to completing a Business Risk Assessment, CDD workflow, and preparing an STR for goAML submission. Coming soon.
Task Management Guide
How to create tasks, dispatch them to employees via magic-link email, collect responses, and route to approval. Coming soon.
EPRS Filing Calendar
How the EPRS filing calendar works, which return types are tracked, and how to log a submission. Coming soon.
goAML STR Submission
How MandateAI generates goAML-compliant XML for Suspicious Transaction Reports and how the MLRO submits them to the UAE FIU. Coming soon.