Skip to content

Part 10 — System Blueprint

Actors Permissions

Access control in SME lending is a credit control, not an admin screen. The model below combines role-based access control (RBAC), attribute-based conditions, maker-checker and Delegation of Authority (DoA). It assumes outsourced DSAs, LSPs, field agents, legal vendors and valuers can access only narrow portals. The regulated entity remains responsible for outsourced acts under RBI’s Digital Lending Directions and recovery-agent conduct instructions, so vendor permissions must be auditable and revocable.

Actor codeHuman roleEmployment boundaryTypical scopeNever allowed
borrower_userBorrower/proprietor/promoter/authorised signatoryExternal customerOwn applications, consents, KFS, documents, service requests, payment linksInternal scorecards, bureau variables, CAM, deviation notes
guarantor_userGuarantor/security providerExternal customerOwn KYC, guarantee documents, notices, NOC status after releaseBorrower financial data beyond guarantee documents
dsa_userDSA/connectorExternal channel partnerSubmit leads, upload documents, view coarse status, view eligible payoutBureau report, CAM, RCU findings, sanction authority, collections notes
partner_api_clientLSP/anchor/co-lender systemExternal systemAPI-scoped application, status, repayment, partner-share exchangeDirect DB access, unapproved personal data, hidden offer manipulation
sales_rmRelationship manager/sales officerFirst lineLeads, application capture, document collection, customer follow-upCredit approval, KYC approval, DPD edit, charge waiver approval
sales_managerASM/RSM/DSA managerFirst lineSource governance, source-code exceptions, DSA payout holds, funnel oversightFinal credit approval unless separately assigned credit authority
sales_opsCRM/login operationsFirst line/control opsLead dedupe, login completeness, checklist generation, source lockKYC override, credit deviation approval
kyc_makerKYC processing officerOperations/controlCDD data entry, CKYC retrieval, document checksFinal KYC approval of own work
kyc_checkerKYC verifier/AML opsControlKYC approval/rejection, BO checks, periodic KYC closureCredit approval, disbursement approval
aml_complianceAML/compliance officerSecond lineSanctions/PEP/adverse media resolution, high-risk KYC approvalBooking payment or waiving dues
credit_analystAnalyst/credit processing officerFirst line creditCAM, financial spreading, ratios, recommendationFinal approval above assigned authority; disbursement release
credit_managerBranch/area/regional credit managerFirst line credit with DoAApproval within DoA, deviations within level, conditionsOwn-source application approval where conflict rule applies
credit_committee_memberCommittee approverCommitteeVote/comment/approve cases routed to committeeEditing application evidence after vote
national_credit_headNational credit authoritySenior managementHigh-value and high-severity approvals, DoA exceptionsOperations maker action on approved case
policy_riskCredit policy/portfolio riskSecond linePolicy rules, BRE versions, monitoring triggers, portfolio capsIndividual loan disbursement approval
rcu_officerRisk/fraud controlSecond lineFI/RCU case review, fraud flags, negative clearanceCredit approval of file cleared by self
legal_userLegal officerControl/vendor managerLegal opinion review, document format, litigation and charge release checksValuation value edit, cash receipt posting
valuer_vendorTechnical valuerExternal vendorAssigned collateral inspection and valuation report uploadApplication data unrelated to assigned asset
legal_vendorEmpanelled advocateExternal vendorAssigned title search/legal report uploadCredit decision, customer contact outside assignment
ops_makerLoan operations makerOperationsCP checklist, documentation verification, disbursement request preparationCheck own disbursement request
ops_checkerLoan operations checkerOperationsDocumentation approval, CP clearance, booking approval within ops authorityCredit approval, own maker action approval
treasury_financeTreasury/finance userControlPayment funding, GL posting, reconciliation, DSA payout, provisionsChange sanction terms or KYC status
servicing_agentCustomer service/servicing officerOperationsStatements, SRs, mandate change intake, NOC workflowWaive charges beyond permitted service-error grid
collections_agentTele/field collectorCollections/vendorAssigned case contact, PTP, visit disposition, payment linkEdit DPD, negotiate waiver without approval, access non-assigned cases
collections_managerBucket/agency managerCollectionsAllocation, escalation, settlement proposal, agency governanceApprove own negotiated settlement above DoA
legal_recoveryRecovery legal managerCollections/legalNotices, litigation, enforcement, repossession, security saleChange LMS dues
compliance_officerCompliance/grievanceSecond lineRegulatory holds, complaint review, policy attestations, audit exportsBook or reverse loan transactions
internal_auditorInternal audit/IS auditThird lineRead-only audit, evidence export, access reviewMaker/checker/approval in live workflow
system_adminIAM/platform adminTechnologyUser provisioning, role assignment, secrets/config under break-glassBusiness approval or customer data export without ticket
system_serviceBatch/integration serviceNon-humanScheduled events, API callbacks, DPD computation, notificationsHuman-only approvals

Legend: C create, R read, U update, A approve/check, X execute/post, V vendor-scoped, O own-record only, N no access.

CapabilityBorrowerDSASales RMSales mgrKYC makerKYC checkerAML/complianceCredit analystCredit approverRCULegalOps makerOps checkerFinanceServicingCollectionsAudit
Lead captureOC/OC/UR/ARRRRRRRRRRNNR
Source-code lock/changeNNCANNRRRRNRRRNNR
Consent captureC/OC/OCRRRRRRRNRRNRRR
Application edit before lockOC/OC/URRRRRRRRURNRNR
KYC data entryC/ONCRC/URRRRRNRRNRNR
KYC approval/rejectionNNNNNAA high-riskNNRNNRNNNR
BO waiverNNNNNRequestANRRNNRNNNR
Document uploadC/OC/OCRCRRRRRC/VC/URNCRR
Document verificationNNNNA KYC docsA KYC docsRRRRA legal docsUANU service docsRR
Bureau/data pull requestConsent onlyNRequestRNRRCRRNNRNNNR
View bureau reportNNNNNR limitedR limitedRRR fraud varsNNNNNNR masked
BRE rule editNNNNNNC policy attestRRRNNNNNNR
BRE rule publishNNNNNNA complianceNNC/U policyNNNNNNR
CAM prepareNNNNNNRC/URRRNNNNNR
Credit approveNNNNNNRRecommendA within DoARRNNNNNR
Deviation approveNNNNNNA regulatory onlyRequestA within DoAA fraud clearanceA legalNNNNNR
Sanction issueR/OR coarseRRNRRC draftARRRA ops packRRNR
KFS acceptC/ONAssistRNNRRRNNRRNRNR
Documentation executionC/ONAssistRNRRRRRC/A legalC/UANRNR
CP clearanceNNRequestRRRRRRRA legal CPC/UARNNR
Disbursement requestNNNNNNRNRNRCAR/X fundingNNR
Payment posting/reversalNNNNNNRNRNNRequestA opsX/A financeNNR
Loan schedule viewONRRNNRRRNRRRRRR assignedR
DPD/SMA/NPA editNNNNNNRNRNNNNNNNR
DPD/SMA/NPA recomputeNNNNNNRNRNNNNRNRR
Service request actionC/ONCRRRR complaintsRRNR legal SRsUARC/URR
Mandate/bank changeC/ONAssistRNNRNNNNCARCNR
Collections contactNNR relationshipRNNR complaintsNRR fraudRNNRRC/U assignedR
PTP recordNNNNNNRNNNNNNRNC/U assignedR
Settlement proposalNNNNNNRRRNRNNRNCR
Settlement/waiver approvalNNNNNNA conductRA creditNA legalNNA financeNA within DoAR
Collateral releaseR/ONRequestRNNRRA credit if conditionNA legalCAA financeCRR
User/access administrationNNNNNNRequestNNNNNNNNNR
Audit exportNNNNNNRNNNNNNRNNC/R
ActionMaker roleChecker/approver roleSeparation ruleMandatory evidenceRegulatory/control reason
Source-code change after loginSales RM or sales opsSales managerChecker cannot be same user or subordinate DSAOld source, new source, reason, customer consent timestampPrevents payout disputes and channel manipulation.
KYC approvalKYC makerKYC checkerChecker cannot verify own entryOVD/entity docs, BO records, screening statusRBI KYC requires CDD, BO and ongoing due diligence evidence.
High-risk KYC/PEP/sanctions clearanceKYC checkerAML/compliance officerAML officer independent of sales and creditScreening report, false-positive rationale, enhanced due diligence noteAML/CFT control under RBI KYC Master Direction.
Document waiverSales/ops requesterOps checker plus function ownerWaiver authority must differ from requesterRequirement, reason, alternate evidence, expiryPrevents silent missing documents.
Credit deviationCredit analystCredit approver at resolved DoA levelApprover cannot be application maker; sales cannot approve creditRule breached, mitigant, severity, DoA levelBoard-approved credit policy and auditability.
RCU negative clearanceRCU officerRCU manager or fraud headCredit/sales cannot close RCU negativeFI/RCU report, fraud signal, closure rationaleFraud-control independence.
Sanction approvalCredit analystCredit approver/committeeRecommender cannot be sole approver above self-approval bandCAM, rule results, deviations, conditionsCredit approval trail.
KFS generation and acceptanceSystem/sales assistBorrower or authorised signatory; ops verifies where assistedStaff cannot accept on borrower behalfKFS version, APR inputs, OTP/e-sign/click evidenceRBI KFS and Digital Lending disclosure duties.
CP clearanceOps makerOps checker/function ownerMaker cannot clear own CPCondition evidence and waiver if applicableDisbursement control.
Disbursement postingOps makerOps checker plus finance releaseChecker cannot be maker; finance funds only approved instructionVerified beneficiary, mandate, CP status, payment instructionDigital lending fund-flow and wrong-beneficiary control.
Bank account change after bookingServicing/ops makerOps checker; fraud/compliance for high-riskMaker cannot check; borrower verification requiredRequest, penny-drop, cancelled cheque/statement, OTPFraud and repayment diversion control.
Manual DPD/classification overrideLMS support/risk makerRisk head plus finance/compliance checkerNo branch/sales overrideSystem computation, correction reason, before/after valuesIRAC and CIC reporting impact.
Charge waiverServicing/collections makerAuthority by amount and reasonNegotiator cannot approve beyond small service-error gridDues breakup, reason, customer communicationPenal charges/KFS conduct control.
OTS/settlementCollections makerDoA authority plus finance/legal where requiredNegotiator cannot approve own OTSRecovery estimate, waiver split, source of funds, OTS letterGovernance over compromise settlements.
Write-offCollections/finance makerFinance head/credit committee/board per DoACollections collector cannot approveProvision, recovery history, legal status, approval noteAccounting and audit control.
Collateral releaseServicing/ops makerLegal plus ops checker plus finance no-duesRelease checker cannot be same makerNo-dues, CERSAI/ROC satisfaction task, vault packetSecurity release control.
Role assignmentSystem adminIAM approver or role ownerAdmin cannot self-grant business approver rolesTicket, manager approval, expiryPrivileged access control.

DoA must be data, not a PDF. The approval service resolves authority from amount, product, collateral, risk grade, unsecured exposure, deviation severity, source channel, group exposure, restructuring/settlement haircut and conflict flags.

FieldTypeConstraintsNullableReferences
authority_level_iduuidPrimary keyNoNone
level_codetextUnique: L1_BRANCH_CREDIT, L2_REGIONAL_CREDIT, L3_ZONAL_CREDIT, L4_NATIONAL_CREDIT, L5_CREDIT_COMMITTEE, L6_BOARD_RISKNoNone
level_rankintHigher rank means higher authorityNoNone
descriptiontextHuman-readableNoNone
active_flagbooleanDefault trueNoNone
FieldTypeConstraintsNullableReferences
authority_rule_iduuidPrimary keyNoNone
rule_versionintImmutable versionNoNone
business_lineenumunsecured_bl, lap, machinery, working_capital, invoice_finance, collections, servicing, co_lendingNoNone
action_typeenumcredit_approval, pricing_deviation, policy_deviation, document_waiver, disbursement_exception, settlement, writeoff, restructure, collateral_release, partner_onboardingNoNone
min_amountnumeric(18,2)Inclusive lower boundNoNone
max_amountnumeric(18,2)Inclusive upper boundYesNone
max_unsecured_amountnumeric(18,2)Applies to unsecured exposureYesNone
risk_grade_settext[]Applicable grades; empty means allNoNone
collateral_type_settext[]Applicable collateral types; empty means allNoNone
max_ltv_percentnumeric(9,6)Null if not applicableYesNone
deviation_severityenumnone, low, medium, high, criticalNoNone
required_authority_level_iduuidOutput levelNoauthority_level.authority_level_id
requires_committee_flagbooleanTrue when quorum/voting is mandatoryNoNone
effective_fromdateRequiredNoNone
effective_todateNull for activeYesNone
FieldTypeConstraintsNullableReferences
approval_request_iduuidPrimary keyNoNone
subject_typeenumapplication, sanction, deviation, disbursement, service_request, settlement, writeoff, restructure, collateral_release, partnerNoNone
subject_iduuidId of subject recordNoNone
action_typeenumSame as authority_rule.action_type plus kyc_high_risk_clearance, access_grantNoNone
requested_byuuidMakerNouser.user_id
required_authority_level_iduuidResolved by approval serviceNoauthority_level.authority_level_id
amount_basisnumeric(18,2)Exposure, waiver or transaction amountYesNone
severity_basisenumnone, low, medium, high, criticalNoNone
statusenumdraft, submitted, approved, rejected, returned, expired, cancelledNoNone
submitted_attimestamptzRequired when submittedYesNone
decision_attimestamptzRequired when terminalYesNone
FieldTypeConstraintsNullableReferences
approval_decision_iduuidPrimary keyNoNone
approval_request_iduuidParent requestNoapproval_request.approval_request_id
approver_user_iduuidApproverNouser.user_id
approver_authority_level_iduuidApprover level at decision timeNoauthority_level.authority_level_id
decisionenumapprove, reject, return, abstainNoNone
decision_notetextRequired except abstainYesNone
decision_attimestamptzRequiredNoNone
conflict_checked_flagbooleanMust be trueNoNone
ConditionRequired levelAdditional rule
Unsecured business loan up to ₹10 lakh, risk grade A/B, no deviationL1_BRANCH_CREDITSingle approver allowed if not sales-linked.
Unsecured ₹10-50 lakh or risk grade CL2_REGIONAL_CREDITRCU status must be clear.
Unsecured above ₹50 lakh or any high-severity policy deviationL4_NATIONAL_CREDITCommittee may be required by policy.
LAP or secured term loan up to ₹1 crore, LTV within policy, clean legal/valuationL2_REGIONAL_CREDITLegal and valuation must be accepted.
LAP ₹1-5 crore or LTV/pricing deviationL3_ZONAL_CREDITLegal exception routes to legal approver too.
Exposure group above ₹5 crore, related-party exposure, new product exceptionL5_CREDIT_COMMITTEECommittee quorum and minutes mandatory.
Board policy breach, portfolio cap breach, unusually large exposureL6_BOARD_RISKBoard/risk committee record required.
ConditionRequired levelRequired co-approval
Service-error charge waiver up to ₹5,000Servicing checkerCompliance sample review.
Penal/bounce/legal charge waiver up to ₹50,000Collections managerFinance if income reversal is needed.
OTS waiver up to ₹2 lakh or up to 10 percent of duesRegional collections headFinance sign-off.
OTS waiver ₹2-25 lakh or 10-25 percent of duesZonal collections/credit committeeLegal and finance sign-off.
OTS waiver above ₹25 lakh or above 25 percent of duesStressed asset/credit committeeLegal, finance and compliance visibility.
Technical write-offFinance head plus credit/recovery committeeBoard reporting as policy requires.
Collateral release after settlementLegal plus ops checker plus finance no-duesPartner approval if co-lent.
GuardExpressionApplies to
Own work cannot be checkedmaker_user_id != checker_user_idAll maker-checker approvals
Sales conflictapprover.function != sales unless role has separate credit authority and did not source fileCredit approvals
Branch/geography limitapprover.allowed_branch_codes contains application.assigned_branch_code or national scopeCredit, ops, collections
Amount authorityapproval.amount_basis <= authority_rule.max_amount and above lower boundCredit, settlement, write-off, disbursement exception
Severity authorityapprover.level_rank >= required_authority.level_rankDeviations and exceptions
Vendor assignment scopevendor_user.assigned_case_ids contains subject_idLegal vendor, valuer, field agency
Partner data scopeapi_client.partner_id == application.source_partner_id and endpoint scope includes actionPartner APIs
Regulatory hold blockNo approval if screening_hit.true_positive_open or compliance_hold.active unless action is hold resolutionKYC, disbursement, booking
Co-lending partner consentRequired when action changes borrower economics, settlement, restructure, DPD correction or collateral release on CLA accountCo-lending accounts
ControlRequirement
Immutable audit eventsEvery approval, rejection, waiver, override, DPD correction, settlement, write-off, bank-account change and role grant writes an immutable audit_event.
Privileged accesssystem_admin cannot grant business approval roles to self; break-glass access expires automatically and is reviewed.
Vendor expiryDSA, valuer, legal vendor, field agency and LSP users require contract, geography, product scope and expiry date.
Data maskingBorrower PAN, Aadhaar last four, bank account, bureau details and phone/email are masked by default outside need-to-know roles.
Quarterly reviewActive users, dormant users, high-risk roles, maker-checker conflicts and vendor accounts are reviewed at least quarterly.
Audit read-onlyInternal audit receives read-only evidence export. Audit users cannot operate workflow actions.