Teams & roles

Your organization is your company’s tenant on RDCPASS. Colleagues join it as members, and each member’s role decides what they can see and change — from creating a sandbox application to issuing production keys or topping up the wallet.

At a glance

  • Six roles: Owner, Administrator, Developer, Financial officer, Compliance officer, Marketing.
  • Exactly one Owner per organization; ownership can be transferred.
  • Members sign in with their own RDCPASS identity — there are no shared accounts and no console passwords.
  • Multi-factor authentication is mandatory for every member, on every sign-in.
  • Every action is recorded in an audit trail attributed to a real, verified person.

Roles

RoleResponsibilities
OwnerEverything, including deleting the organization and transferring ownership. One per organization — usually the legal representative or CTO.
AdministratorManages members, applications, scopes, production requests and keys.
DeveloperCreates and edits sandbox applications, issues sandbox keys, configures webhooks, reads request logs. Cannot issue production keys or change the scopes of production applications.
Financial officerBilling: prepaid or postpaid plan, wallet top-ups, invoices, usage exports and spending alerts.
Compliance officerThe due-diligence dossiers, scope justifications and purposes, audit logs and data-access reviews.
MarketingRead-only usage analytics, the application listing and branding (logo and consent-screen texts for Login with RDCPASS).

Permission matrix

✓ allowed · “Sandbox” allowed on sandbox applications only · — not allowed.

PermissionOwnerAdmin.DeveloperFinancialComplianceMarketing
Invite and remove members, change roles
Transfer ownership, delete the organization
Create and edit applicationsSandbox
Issue sandbox keysSandbox
Issue production keys and mTLS certificates
Change scopes and purposes of production applications
Configure webhooks and IP allowlistSandbox
View request logs
Submit due-diligence dossiers
View usage analytics
Manage billing (plan, top-ups, spending alerts)
View invoices and export usage
Manage app listing and consent-screen branding
View and export the audit log

A member can hold more than one role; their permissions are the union of those roles. Owners and Administrators can change roles at any time, and changes apply on the member’s next request.

Inviting members

1
Open Team in the console
An Owner or Administrator opens Settings → Team in the console and selects Invite member.
2
Enter the email and choose roles
Enter the colleague’s work email address and select one or more roles. Invitations expire after 7 days.
3
The colleague accepts with RDCPASS
The invitee opens the link and signs in with their own RDCPASS identity. Their verified name is attached to their membership — it cannot be edited by anyone in your organization.
4
Membership is active
The new member appears in the team list with their roles, and the invitation, acceptance and roles are recorded in the audit trail.

Only people holding a certified RDCPASS account can accept an invitation. Colleagues who are not Congolese residents can obtain one through the RDCPASS enrolment process for foreign nationals.

Sign-in and multi-factor authentication

Members sign in to the console with Login with RDCPASS: they approve the sign-in in the RDCPASS mobile app with a push notification and a face check. This is the same strong authentication citizens use, so there is no password to steal, share or reset. Multi-factor authentication cannot be disabled. Console sessions expire after 12 hours, and sensitive actions — issuing production keys, changing production scopes, changing the billing plan — ask for a fresh confirmation in the app.

No shared or generic accounts

Accounts such as “it@company.cd” shared by several people cannot exist: every membership is bound to one person’s RDCPASS identity. This is what lets RDCPASS and your auditors attribute every action to an accountable individual.

Removing members and transferring ownership

Removing a member revokes their console access immediately. Application keys keep working, because they belong to applications, not people — but rotate any key set the departing member had access to. To transfer ownership, the Owner selects an Administrator as the new Owner; the transfer completes once the new Owner confirms in the RDCPASS app, and the previous Owner becomes an Administrator.

Separation of duties

RDCPASS reviewers look at how duties are split during due diligence. We recommend:

Keep production keys with a small group
Give Administrator only to the people who deploy to production. Most engineers need Developer only.
Separate billing from engineering
Assign billing to a Financial officer who is not an Administrator, so spending and technical access are controlled by different people.
Give compliance an independent seat
Your data-protection officer or compliance lead should hold Compliance officer and review scope justifications and the audit log — ideally without holding Administrator.
Name at least two Administrators
Avoid a single point of failure for key rotation and incident response.
Review membership every quarter
Remove leavers the day they leave and check that each member still needs their roles.

Audit trail

Organization-level actions — invitations, role changes, removals, ownership transfers, billing changes and dossier submissions — are recorded alongside each application’s audit log. Each entry records the member’s RDCPASS identity, role, timestamp, IP address and the values before and after. Owners, Administrators and Compliance officers can export the trail; entries are retained for five years and cannot be edited. See Applications for the audit event format.

Next steps

Questions about your integration? Contact developer support