Customer and Engagement Roles
At the organization level:
- Customer Admin — can create engagements, add and manage users across the organization, and see usage reporting.
- Customer User — can only access engagements where they've been given an explicit role. This is the default on user creation.
At the engagement level:
- Engagement Owner — full working rights plus the ability to manage who else can access this specific engagement, delete statements and check images, and run destructive actions. Think of this as the project lead.
- Engagement User — full read and edit rights for this engagement. Can work with transactions, run matches, create stories, and export data. Cannot manage other users, delete statements, or run certain bulk actions that are restricted on forensic engagements.
| Action | Engagement User | Engagement Owner | Customer Admin (without Engagement Owner on this engagement) |
|---|---|---|---|
| View transactions, statements, and exports | Yes | Yes | Only if explicitly assigned to this engagement |
| Edit transactions, add stories, run categorization | Yes | Yes | Only if explicitly assigned |
| Run matches, Excel Sync imports | Yes (owner-only on some engagements — see below) | Yes | Only if explicitly assigned |
| Delete a statement or check image | No | Yes | Only if they also hold Engagement Owner on this engagement |
| Manage users for this engagement | No | Yes | Yes, if explicitly assigned at any level |
| Create a new engagement | No | No | Yes |
Bulk match actions are stricter on forensic engagements than audit engagements. If you're an Engagement User on a forensic engagement and actions like resetting all matches or bulk-approving transfers are unavailable, that's expected — those operations require Engagement Owner on a forensic engagement while they may be available to Engagement User on an audit engagement. The product does not label which type your engagement is, so the easiest way to tell is whether the action is available.
Common confusion: "I'm an admin and I can't delete this file"If you're a Customer Admin and a processed file's delete option is unavailable or grayed out, the most common cause is that you don't hold Engagement Owner on this specific engagement — only Customer Admin at the organization level.
If you need read-only accessThe product does not currently offer a true view-only or read-only role at the engagement level. If you need to give someone visibility into an engagement's data without edit rights, the closest available option is Engagement User — but that role can edit transactions, create stories, and run matches, so it is not genuinely read-only.
If your situation requires stricter access control than the current role model supports, contact support with your use case — for example, granting outside counsel or an auditor limited visibility — so they can help you determine the safest available path.
Creating an engagement, and the missing "+" buttonCreating a new engagement requires Customer Admin, not Engagement Owner. If you're an Engagement Owner on several projects but the "+" button to create a new engagement is missing or grayed out, that's why — you need Customer Admin status at the organization level, not just project-level ownership.
If you're seeing "Error creating the customer user"This error has two common causes:
- Your organization is configured for enterprise SSO, and manual user creation is disabled. The full message behind the generic toast reads
Manual user creation disallowed. Users must be created through the IDP. If this is your situation, users must be provisioned through your identity provider (your company's single sign-on system), not added directly in Valid8. - The email address is already registered elsewhere in the system. The message behind the toast reads
An user with email {email} already exists. This can happen if the person previously had an account under a different organization, or if their account was deleted and hasn't been fully cleared. Contact support with the email address and organization name if you're stuck on this.