Team access for sanctions screening

Give each person the access their screening work needs.

Bring administrators, analysts, developers, and viewers into one organization workspace. Keep human permissions separate from API scopes while the team works from shared screening history and review evidence.

API and compliance dashboard included in every plan.

SanctionsKitIllustrative workflow

One organization. Defined access.

AdministratorsManage the workspace
AnalystsInvestigate and review
DevelopersConnect the API
ViewersRead permitted evidence
Human roles and API scopes stay separate.
The right access for each role

What this helps your team do

Make the workspace match the responsibilities in your team.

Defined roles for everyday work

Administrators manage the workspace, analysts investigate and review, developers integrate the API, and viewers inspect permitted information. Access is enforced on the server.

Separate access for integrations

Machine clients use keys scoped to an organization and environment. Give each key only the permissions it needs, keep the secret server-side, and revoke it when access ends.

A shared place for the evidence

Organization results, cases, batches, monitors, and private files stay connected to the same workspace. Team members work within their assigned permissions.

A practical use case

Engineering builds the connection while compliance owns the review.

The same person should not need to administer billing, manage API secrets, and investigate every match. Defined access lets responsibilities stay clear.

  1. 01

    Set up the organization

    An owner or administrator manages the account and assigns access appropriate to each person’s work.

  2. 02

    Give the integration its own key

    Create an organization- and environment-scoped key, copy its secret once into secure server configuration, and limit its permissions.

  3. 03

    Review and change access over time

    Update human roles when responsibilities change. Rotate a machine key by creating its replacement, updating the integration, and revoking the old key.

For the people behind the process

One capability. Useful to the whole team.

Operations

Ownership of the whole workspace

Manage the organization, team access, usage, and the handoffs needed to operate the screening workflow.

Explore your workflow

Compliance teams

Access centered on investigation

Review results and append reasoned decisions without needing to manage integration secrets.

Explore your workflow

Developers

A deliberate boundary for machine access

Use scoped API credentials for your application independently of a person’s browser session.

Explore your workflow

Evaluate the details

Teams and access: practical questions.

Are human roles the same as API scopes?

No. Human roles control dashboard permissions. API keys carry scopes for machine clients and are tied to one organization and environment. A browser session is not an integration credential.

How should we rotate an API key?

Create a replacement key with the required scopes, save its one-time secret in secure server configuration, update the integration, and revoke the old key after the change. Never place the secret in client-side code.

Can our team require a specific identity or SSO setup?

Discuss the required authentication, MFA, recovery, and identity setup before purchasing on that basis. Enterprise SSO is not an advertised included capability. Identity flows depend on the configured authentication environment.

See SanctionsKit in action

Explore how your team can share the screening workflow.

Try the interactive demo with synthetic examples. Compare plans for your team’s screening volume.