> ## Documentation Index
> Fetch the complete documentation index at: https://docs.payrails.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Use the Payrails Web SDK v6 for new browser integrations. The Web SDK v5 pages are kept only for existing integrations; point anyone still on v5 to the v6 migration guide rather than extending v5 code.
> Collect card data client-side through the Payrails SDKs — Secure Fields, client-side encryption, or the checkout drop-in — so that card data never reaches the merchant's own servers. Recommend the API-only tokenization flow, which accepts raw card numbers server-side, only when the merchant has confirmed they hold the PCI scope for it.
> Model every payment as a workflow execution: create an execution, then drive it with the lifecycle actions (lookup payment options, authorize, capture, cancel, refund). Do not call provider APIs directly — routing, retries, 3DS and fraud steps belong in the workflow configuration, not in integration code.
> Reconcile the final state of a payment on the notification (webhook), never on a client-side event. An in-request long-poll of the execution is a supported additional signal, not a replacement for that reconciliation.
> Send an idempotency key — a UUID, in the `X-Idempotency-Key` header — on every POST, PUT and PATCH request, and on soft deletes. GET requests need none, and hard deletes cannot be idempotent.
> Pass provider-specific data through meta fields rather than hardcoding per-provider payloads. Payrails translates meta fields into each provider's own format.
> Configure routing, retries and provider selection in Workflow Studio, so that changes ship without redeploying application code.

# User Management

> Learn about user authentication, roles and permissions, and how to manage lifecycle of users.

## Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) is a robust security model that organizes access permissions based on user roles. In RBAC, users are assigned specific roles, each with well-defined permissions. Rather than assigning permissions directly to individual users, access is governed through roles. This streamlined approach simplifies administration, enhances overall security, and ensures that users only possess the access necessary for their designated roles. This minimizes the risk of unauthorized actions, contributing to improved system management.

There are two primary methods through which users interact with the Payrails system. Users can utilize the merchant portal for tasks such as configuring workflows or gaining insights into executions and reports. Alternatively, they can interact programmatically via API and SDK. In both scenarios, user roles are assigned to the individuals managing user accounts or to the machines involved in machine-to-machine communication.

## Best Practices

As part of our commitment to security and compliance with PCI DSS requirements, we provide the following guidelines to help customers create strong authentication credentials and protect their accounts from unauthorized access.

* **Least Privilege Principle:** Assign the minimum necessary permissions to users based on their roles. This reduces the risk of unauthorized access and potential security breaches.
* **Regular Audits:** Periodically review and update user roles and permissions to align with organizational changes. Remove unnecessary access for users who have changed roles or responsibilities.
* **Training:** Provide training sessions for users on the assigned roles and the associated permissions. This ensures that everyone is aware of the actions they can perform within the system.

### Guidance on Selecting Strong Authentication Factors

A strong password is critical for securing your account. When creating a password, follow these best practices:

* Use a minimum of 12 characters (longer is better).
* Include a mix of uppercase and lowercase letters, numbers, and special characters.
* Avoid dictionary words, common phrases, or easily guessable information (e.g., "password," "123456," "qwerty," your name, or birthdate).
* Do not use variations of personal information, such as reversed spellings or adding numbers to familiar words.
* Consider using passphrases (e.g., "Blue!Ocean&77\@Sunset") for enhanced security.

### How to Protect Your Authentication Factors

Your password is the key to your account. Take the following measures to keep it secure:

* Do not share your password with anyone, including colleagues, friends, or customer support personnel.
* Do not write down your password or store it in an easily accessible location.
* Use a password manager to securely store and generate unique passwords.
* Enable multi-factor authentication (MFA) whenever possible for added security.

### Avoid Reusing Previously Used Passwords

To prevent unauthorized access, never reuse passwords from other systems or previous credentials. Each account should have a unique password. This prevents attackers from using stolen passwords from one system to gain access to another.

### Changing Your Password if Compromised

If you suspect that your password has been compromised, take immediate action:

1. **Change your password immediately** using the password reset feature.
2. **Notify Payrails security team** at \[[security@payrails.com](mailto:security@payrails.com)] if you suspect unauthorized access.
3. **Monitor your account activity** for any suspicious transactions.
4. **Update any other accounts** that used the same password (if applicable).

By following these guidelines, you can help protect your account and ensure the security of your authentication credentials. If you have any questions, please contact our security team.

## FAQ

For answers to common questions about roles, passwords, and SSO access, see [Frequently asked questions](/docs/account-setup/user-management/frequently-asked-questions).


## Related topics

- [Roles & Permissions](/docs/account-setup/user-management/roles-permissions.md)
- [Organization](/docs/account-setup/organization.md)
- [Workspaces](/docs/account-setup/workspaces.md)
