Read one company role
Returns effective permission IDs and the current lockVersion for one of the four company defaults. Company permission: `getCompanyRole`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
code*stringCompany role and effective permissions
*/*- response
code?stringdefaultPermissions?booleanid?stringuuidlockVersion?integerint32name?stringpermissions?array<string>curl -X GET 'https://api.monetaryai.uz/api/v1/settings/roles/string'{ "code": "string", "defaultPermissions": true, "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "lockVersion": 0, "name": "string", "permissions": [ "string" ]}List the four company default roles GET
Always returns ADMIN, ACCOUNTANT, MANAGER and EMPLOYEE with effective permission IDs and optimistic lock versions. Permission customization is isolated to the signed tenant. Company permission: `listCompanyRoles`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.
List company users for the settings table GET
Bounded page with company display name, immutable login email, role codes, ACTIVE/SUSPENDED status, last login and lockVersion. ENDED memberships are hidden but retained for audit. Search matches literal name/email substrings; role and status filters are optional. Add a user through the recipient-bound invitation API, never by setting another person's password. Company permission: `listCompanyUsers`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.