Access and Governance
RBAC directory, role matrix and the maker-checker approvals inbox
Patrick Habimana - Platform Admin
4 approvals awaiting you
Maker-checker: a change is applied only after a checker who is not the maker approves it. Config and ledger changes below are held pending your decision.
What this screen is answerable for. The approvals inbox is one queue for every kind of maker-checker item on the platform: config versions, ledger corrections, blocklist changes, role changes, consent purpose definitions, data rights fulfilment, session revocations, lending policy and recruiter programme changes.
Commission plan v14Config
Maker: Grace Umutoni - raised 1h ago - effective 01 Aug 2026
Compensating ledger entry JE-99310Ledger
Maker: Samuel Nsengimana - raised 2h ago - suspense clearing
Blocklist addition +250 788 000 114Risk
Maker: Emmanuel Bizimana - raised 3h ago - FRAUD-8842
Role change - Josiane to KYC ApproverAccess
Maker: Patrick Habimana - raised 5h ago - needs another checker
Commission plan v14
Pending checkerCFG-1043 - marketplace commission - maker Grace Umutoni - requested 20 Jul 2026 11:04
Field
Current (v13)
Proposed (v14)
Electronics commission
8.0%
7.5%
Groceries commission
5.0%
5.0%
Fashion commission
12.0%
11.0%
Instant settlement fee
1.0%
0.9%
Effective from
01 Jul 2026
01 Aug 2026
Change reason (maker): Q3 seller incentive - reduce commission on electronics and fashion to grow GMV. Approved by category P&L review.
Segregation of duties: you did not raise this change, so you are eligible to approve it. The maker cannot self-approve.
| User | Role | Domain scope | MFA | Last active | Status | Actions |
|---|---|---|---|---|---|---|
PH
Patrick Habimana patrick.h@efashe.rw |
Platform Admin | All domains | TOTP | 2 min ago | Active | Manage |
GU
Grace Umutoni grace.u@efashe.rw |
Config Administrator | Configuration, Pricing | TOTP | 12 min ago | Active | Manage |
SN
Samuel Nsengimana samuel.n@efashe.rw |
Ledger Operator | Wallet, Ledger | TOTP | 1 h ago | Active | Manage |
EB
Emmanuel Bizimana emmanuel.b@efashe.rw |
Fraud Analyst | Risk and AML | TOTP | 3 h ago | Active | Manage |
JU
Josiane Uwimana josiane.u@efashe.rw |
KYC Reviewer | Identity | Enrolment due | Yesterday | Active | Manage |
CM
Claudine Mukamana claudine.m@efashe.rw |
MLRO / Compliance | Risk, Reports, SAR filing | TOTP | 40 min ago | Active | Manage |
JB
Jean Bosco Niyonzima jeanbosco.n@efashe.rw |
Care Agent | Care, read-only wallet | Disabled | 6 days ago | Suspended | Reinstate |
Note: a role change is itself a maker-checker action. Suspending a user immediately revokes their sessions and access tokens.
Permissions per role. MC means the action is allowed but requires a distinct checker.
| Permission | Platform Admin | Config Admin | Ledger Operator | KYC Reviewer | Fraud Analyst | MLRO | Care Agent | Auditor |
|---|---|---|---|---|---|---|---|---|
| View operations dashboard | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Post journal / compensating entry | MC | - | MC | - | - | - | - | - |
| Approve ledger entry (checker) | Yes | - | Yes | - | - | - | - | - |
| eMoney issuance / liquidation | MC | - | MC | - | - | - | - | - |
| Decide KYC / KYB (Tier 3 checker) | MC | - | - | MC | - | - | - | - |
| Fraud actions (freeze, hold, step-up) | Yes | - | - | - | Yes | Yes | - | - |
| Blocklist / watchlist change | MC | - | - | - | MC | MC | - | - |
| Approve SAR filing | - | - | - | - | - | Yes | - | - |
| Change config / fee / commission plan | MC | MC | - | - | - | - | - | - |
| Manage users and roles | MC | - | - | - | - | - | - | - |
| View WORM audit log | Yes | - | - | - | - | Yes | - | Yes |
Audit: every grant, revoke and approval is written to the hash-chained, append-only WORM audit store with a 10 year retention floor. Nothing in this matrix can be edited without a second approver.
Dry run result
Nothing has been published. This is what the change would do.
A dry run evaluates the proposed value against sample
inputs and returns the outcome difference. It is the Phase 1 way of seeing a config change before
it goes live, and it touches nothing.
| Sample input | Current value | Proposed value | Difference |
|---|---|---|---|
| Electronics order, RWF 189,000 | Commission RWF 15,120 at 8.0% | Commission RWF 16,065 at 8.5% | + RWF 945 |
| Groceries order, RWF 32,500 | Commission RWF 1,625 at 5.0% | Commission RWF 1,625 at 5.0% | No change |
| Fashion order, RWF 65,000 with a flash sale fee | Commission RWF 6,500, fee RWF 0 | Commission RWF 6,500, fee RWF 0 | No change, stacking rule unchanged |
| Order with a corporate voucher | Commission on gross | Commission on gross | No change |
Merchants affected
148
Electronics only
Monthly revenue effect
+ RWF 1.9M
On last month's volume
Merchants worse off by 5%+
0
No plan floor is breached
A dry run is not an approval. Publishing still needs a change reason,
an effective date and a second operator.
Invite an operator
An operator is a named person with a role, never a shared account. Roles are what maker-checker is built on, so the role decides what they can submit and what they can confirm.
Phase 1 is Rwanda only.
No role can both make and check the same thing. The platform refuses a role pairing that would let one person approve their own submission, so you cannot configure your way around it.
Access and Governance
The approvals inbox is clear
Nothing is waiting on a checker
An empty inbox is stated rather than shown as a blank table, because a blank table looks like a loading failure. Eleven items were decided today and none is outstanding.
Access and Governance
You submitted this, so you cannot confirm it
The approve action is unavailable to you on this item. You are Grace Nyirahabimana and you submitted commission plan v14 at 09:14. Confirming your own submission would make maker-checker a formality, so the control is absent rather than present and refusing.
| Error the platform returns | 403 SELF_APPROVAL_FORBIDDEN |
| Item | Marketplace commission plan v14 |
| Maker | g.nyirahabimana, that is you |
| Eligible checkers | 4 operators hold the config approver role |
| Notified | All four, when you submitted it |
| Your options | Withdraw it, or wait. There is no third option. |
| Operator | Role | Can confirm this | Why |
|---|---|---|---|
| g.nyirahabimana | Config maker and approver | No | You are the maker on this item |
| t.nkusi | Config approver | Yes | Available now |
| m.habimana | Config approver | Yes | Available now |
| j.mukama | KYC approver | No | Wrong role. A KYC approver cannot confirm a config change. |
Holding both roles is allowed. What is not allowed is using both on the same item, which is a per item rule rather than a per person one. A small operations team can still function.
Access and Governance
This item was decided while you had it open
Somebody else already decided this. Compensating ledger entry JE-99310 was approved by t.nkusi at 09:41 today, so your decision was refused rather than silently overwriting theirs. The platform returns a state conflict, and that is the right answer: two operators deciding the same item is exactly what maker-checker is meant to catch.
| Error returned | 409 STATE_CONFLICT |
| Item | Compensating ledger entry JE-99310 |
| Already decided by | t.nkusi |
| When | 09:41 today |
| Outcome that stands | approved |
| Your action | Discarded. Nothing was written. |
Why the queue let you open it. The list was loaded before they decided. Refreshing the queue removes it, and any decision you were part way through is lost rather than applied to a closed item.