The Right Access for Every Team Member — With a Full Audit Trail

Regulators expect you to know who touched what data and when. Quantoflow's three-tier permission system ensures every team member has exactly the access they need — and every action they take is permanently logged, searchable, and ready to present at a moment's notice.

When FINTRAC Asks "Who Did What?" — You'll Have the Answer

Regulatory audits aren't theoretical. When an examiner asks to see who uploaded a report, who approved it, or who deleted a record and why, you need a clear, provable answer — not a manual hunt through email threads or spreadsheets. Quantoflow's role system and audit logs give you that answer instantly.

User Role — Your Day-to-Day Compliance Team

Built for: Report handlers, compliance assistants, and team members who work with client data daily.

What they can do:

  • View all reports and client data
  • Upload new reports
  • Update existing reports with corrections or additional information

What they can't do (by design):

  • Delete reports — preventing accidental data loss before it becomes a compliance incident
  • Access audit logs or analytics — keeping sensitive oversight functions in the right hands

Your users are where compliance work happens. Every report they upload or update is automatically timestamped and attributed to their account. The no-delete restriction isn't a limitation — it's a safety net that protects your compliance record from human error.

Admin Role — Your Quality Control and Oversight Layer

Built for: Senior compliance officers, team leads, and quality assurance personnel who need full visibility.

What they can do:

  • Everything Users can do (view, upload, update reports)
  • Delete reports when necessary (with every deletion fully logged)
  • Review complete audit logs — see exactly who did what, and when
  • Access statistics and analytics dashboards to monitor team performance

Admins provide the oversight layer that keeps your compliance operation accountable. When something needs to be deleted — a duplicate filing, a test record — admins can do it, and the audit log captures the full context. Nothing disappears without a trace.

Super Admin Role — Organizational Control and Governance

Built for: Organization owners, compliance directors, and senior management responsible for team structure.

What they can do:

  • Everything Admins can do (delete, audit logs, analytics)
  • Add, remove, or modify admin accounts
  • Manage user access and permissions across the organization

Super Admin is the only role that can change your organizational structure. Every admin change, role assignment, and access modification is captured in the audit trail — so there's always a clear, tracked record of who has what authority and when that changed.

An Audit Trail That Never Lies — and Can Never Be Altered

Every significant action in Quantoflow is automatically, permanently logged:

What gets recorded:

  • Report uploads — file details, timestamp, user
  • Report updates and modifications — what changed, who changed it, when
  • Report deletions — who deleted it, when, and what it contained
  • User role changes and permission modifications
  • Admin account management actions and access revocations
  • Access to statistics and sensitive data

Why this matters in practice:

  • Satisfy FINTRAC examiners: Prove exactly who accessed what data and when — with exportable, searchable logs
  • Internal accountability: Track team performance and address issues with authoritative evidence
  • Fraud and anomaly detection: Spot unusual access patterns before they become incidents
  • Dispute resolution: Settle any question about data changes with immutable timestamps and user attribution

Audit logs are immutable — once recorded, they cannot be altered or deleted by anyone, including Super Admins. That's not a constraint; it's a guarantee your regulators and clients can rely on.

Scales From a Solo Practitioner to a Full Compliance Team

When you create your Quantoflow account, you're automatically set up as a Super Admin. From there, it takes minutes to:

  1. Invite team members as Users for day-to-day report handling
  2. Promote trusted team members to Admin for oversight, deletion authority, and audit log access
  3. Manage admin access as your team evolves — every change tracked in the audit log
  4. Pull audit log reports on demand for internal reviews or regulatory examinations

Whether you're a single compliance officer who wears all three hats or a team of twenty with strict separation of duties, the role system scales to match your structure — without added complexity.

Prove Your Compliance Program Is Working

The question isn't whether you have controls in place — it's whether you can demonstrate them. Quantoflow's role system and audit trail give you the documentation to prove your compliance program meets regulatory expectations, every time someone asks.

Schedule a demo to see how Quantoflow's access controls and audit logging support your team's compliance obligations.