Owner
Full control of the firm: settings, members, and every approval (IC, closing, valuations, funds, reports).
Can invite and assign any roleAcquifolio workspaces belong to an organization. Roles decide who can read or change each area, scoped grants decide what outside parties can see, and the server checks both on every request — the interface only reflects them.
Every member has one role per organization. A person can belong to several organizations with a different role in each.
Full control of the firm: settings, members, and every approval (IC, closing, valuations, funds, reports).
Can invite and assign any roleManages settings, members and records. Cannot vote at IC or issue approvals.
Can invite and assign any role except Owner and AdminInvestment lead: works every module and approves IC, closings, valuations and reports. Cannot manage members.
Cannot invite or change membersWorks deals end to end: financial quality, models, diligence, data room and financing.
Cannot invite or change membersRuns fund operations, capital events and allocator analytics. Read access to records and portfolio.
Cannot invite or change membersManages owned companies, plans and exit readiness. Read access to deals.
Cannot invite or change membersRead-only across internal workspaces (no audit log).
Cannot invite or change membersExternal advisor, counsel, lender or seller. Sees only the deals, folders or companies explicitly granted.
Access only through scoped grantsLP / co-investor. Investor portal only, limited to their own interests.
Investor portal only, through investor grantsA grant gives one person read or write access to one deal, folder, company, fund or investor record, with an optional expiry. Expired grants stop working but stay on record for attribution.
Created by Owners and AdminsOrganization-wide permissions by role, copied from the role map the API enforces (contracts/permissions.ts). A request outside a role’s permissions — and any active grant — is refused, whatever client sends it.
Scroll sideways to see every role.
| Permission | Owner | Admin | Partner | Deal team | Finance | Operator | Viewer | Guest | Investor |
|---|---|---|---|---|---|---|---|---|---|
| Organization | |||||||||
Manage organization settings, modules and workflow rulesorg.manage | Allowed | Allowed | Not allowed | Not allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Invite members, change roles, grant accessmembers.manage | Allowed | Allowed | Not allowed | Not allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Read the audit logaudit.read | Allowed | Allowed | Allowed | Not allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Read companies, contacts, tasksrecords.read | Allowed | Allowed | Allowed | Allowed | Allowed | Allowed | Allowed | Only through a grant | Not allowed |
Edit companies, contacts, tasksrecords.write | Allowed | Allowed | Allowed | Allowed | Not allowed | Allowed | Not allowed | Only through a grant | Not allowed |
| Deals & diligence | |||||||||
Read dealsdeals.read | Allowed | Allowed | Allowed | Allowed | Not allowed | Allowed | Allowed | Only through a grant | Not allowed |
Create and edit dealsdeals.write | Allowed | Allowed | Allowed | Allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Override a stage gate (exception)deals.stage_exception | Allowed | Allowed | Allowed | Not allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Review earnings evidence (QoE)qoe.review | Allowed | Allowed | Allowed | Allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Release an underwriting modelmodels.release | Allowed | Allowed | Allowed | Allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Run diligence requests and findingsdiligence.write | Allowed | Allowed | Allowed | Allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Manage the data roomdataroom.manage | Allowed | Allowed | Allowed | Allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
| Committee, financing & closing | |||||||||
Vote at investment committeeic.vote | Allowed | Not allowed | Allowed | Not allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Record the IC decisionic.decide | Allowed | Not allowed | Allowed | Not allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Edit financing and lender proposalsfinancing.write | Allowed | Allowed | Allowed | Allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Confirm a closingclosing.confirm | Allowed | Not allowed | Allowed | Not allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
| Portfolio & exit | |||||||||
Read portfolio resultsportfolio.read | Allowed | Allowed | Allowed | Allowed | Allowed | Allowed | Allowed | Only through a grant | Not allowed |
Report results, run plansportfolio.write | Allowed | Allowed | Allowed | Not allowed | Not allowed | Allowed | Not allowed | Only through a grant | Not allowed |
Approve valuationsvaluations.approve | Allowed | Not allowed | Allowed | Not allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Read exit readinessexit.read | Allowed | Allowed | Allowed | Allowed | Not allowed | Allowed | Allowed | Only through a grant | Not allowed |
Prepare exit readiness and offersexit.write | Allowed | Allowed | Allowed | Not allowed | Not allowed | Allowed | Not allowed | Only through a grant | Not allowed |
| Funds & investors | |||||||||
Read funds and capital activityfunds.read | Allowed | Allowed | Allowed | Not allowed | Allowed | Not allowed | Allowed | Only through a grant | Not allowed |
Record capital activity and draftsfunds.write | Allowed | Allowed | Allowed | Not allowed | Allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Approve calls, distributions, releasesfunds.approve | Allowed | Not allowed | Allowed | Not allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Read LP Lens analysislplens.read | Allowed | Allowed | Allowed | Not allowed | Allowed | Not allowed | Allowed | Only through a grant | Not allowed |
Edit LP Lens analysislplens.write | Allowed | Allowed | Allowed | Not allowed | Allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Investor portalportal.read | Not allowed | Not allowed | Not allowed | Not allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Allowed |
| Intelligence, learning & reports | |||||||||
Read docket intelligenceintel.read | Allowed | Allowed | Allowed | Allowed | Not allowed | Not allowed | Allowed | Only through a grant | Not allowed |
Edit watchlists and deadlinesintel.write | Allowed | Allowed | Allowed | Allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Use Academyacademy.use | Allowed | Allowed | Allowed | Allowed | Allowed | Allowed | Allowed | Only through a grant | Not allowed |
Manage Academy cases and cohortsacademy.manage | Allowed | Allowed | Allowed | Not allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
Read reportsreports.read | Allowed | Allowed | Allowed | Allowed | Allowed | Allowed | Allowed | Only through a grant | Not allowed |
Issue reportsreports.issue | Allowed | Not allowed | Allowed | Not allowed | Not allowed | Not allowed | Not allowed | Only through a grant | Not allowed |
| Files | |||||||||
Download filesfiles.read | Allowed | Allowed | Allowed | Allowed | Allowed | Allowed | Allowed | Only through a grant | Not allowed |
Upload files and new versionsfiles.upload | Allowed | Allowed | Allowed | Allowed | Allowed | Allowed | Not allowed | Only through a grant | Not allowed |
“grant” means an external guest has no organization-wide access; they reach only the specific records granted to them. Admins cannot change or remove Owners or other Admins, and an organization always keeps at least one Owner.
An Owner or Admin invites an email address with a role they may assign — and, for guests and investors, the grants they receive.
Acquifolio returns the invitation link once. Only a hash of its token is stored.
The inviter shares the link through their own channel — Acquifolio does not send email yet.
The recipient sets a password (or confirms an existing account) within seven days. Pending invitations can be revoked.
Assistance drafts and organizes internal work; authorized people decide. Neither acts on its own outside the workspace.
Plan any use with external participants or regulated data around these boundaries; the product says so where they apply.
Single sign-on uses OpenID Connect only. There is no SAML, no SCIM provisioning or deprovisioning, no IdP-initiated login and no single logout.
MFA uses authenticator-app codes. Passkeys / WebAuthn, SMS or email codes and “remember this device” are not available.
Invitation links are copied and shared by the inviter. Notices, digests and assignments are not emailed, and there is no email-based password reset; screens that would need email say so.
Files are stored on the API server’s disk behind a storage abstraction; managed object storage is planned.
Uploads are checked for type and size, not scanned for malicious content.
Scanned PDFs and images are not read; text is extracted only from PDF, docx and xlsx files that contain text.
Acquifolio holds no SOC 2, ISO 27001 or similar certification, and does not claim one.
The trust page explains how financial evidence and review decisions stay distinct; the roadmap shows what is available and what is planned.