“Security is my number one priority. I need 100% accuracy; anything less isn’t an option. That’s one of the main reasons I like The Mortgage Office—security, reliability…
User Management
Control team access with precision and confidence.
Assign role-based permissions across every module, restrict sensitive actions down to the individual task, and track who did what with a complete audit trail.
JUMP TO:
SEE THE DIFFERENCE
Take control of platform access.
Giving every user full access, or sharing a single login, exposes your data to accidental changes, deletions, and gaps in accountability. With TMO, you decide exactly which modules and actions each person can reach, assign permissions by role in seconds, and keep a complete record of every action taken.
- Grant access by module and by action, down to the individual task
- Assign permissions by role using reusable groups
- Track changes with a built-in audit trail
Platform Features
Give every role the right level of access.
Granular Permissions
Grant access at the module and action level so each user sees only what their role requires. Turn individual capabilities, like editing, posting, or deleting, on or off for any user.
- Control access to each system, from Loan Servicing to Trust Accounting
- Enable or restrict specific actions like add, edit, post, and delete
- Protect critical records by removing delete rights for loan files, funding, and history
Roles & Groups
Build a permission set once and apply it to everyone who shares a role. Create a group for originators, servicers, or any team, then add users without configuring each account by hand.
- Set up reusable groups that match how your team works
- Assign new users to a group instead of building access from scratch
- Adjust access anytime, turn permissions on or off as roles change
Oversight & Accountability
Know who did what, and when. The events journal records every transaction and change across the database, while access controls keep sensitive data and irreversible actions limited to the people you trust.
- Track every payment, edit, and change in the events journal
- Restrict the events journal to administrators and supervisors
- Mask sensitive data like TINs for all but authorized users
HOW IT WORKS
Manage Users easily.
Step 1
Define roles
Identify the access each role needs, originators, servicers, administrators, based on the work they actually do.
Step 2
Build groups
Create a permission group for each role, setting module and action access once.
Step 3
Assign Users
Add each user to the right group to grant the correct access instantly, with no per-user setup.
Step 3
Monitor and adjust
Use the events journal to track activity, and update permissions anytime as your team changes.
See User Management controls in action.
SECURITY, COMPLIANCE & PERMISSIONS
Strengthen internal controls and audit readiness.
Limit access to the people who need it, prevent accidental or unauthorized changes, and maintain a clear record of every action. Strong user controls reduce fraud risk and support the segregation of duties examiners expect.
- Apply least-privilege access so users reach only what their role requires
- Prevent unauthorized deletions and edits to protect data integrity
- Maintain a complete audit trail for every user action
Partnerships & Integrations
Leverage User Management controls and our robust servicing platform with your team’s existing tools and other powerful integrations to keep payment data accurate, reduce manual work, and strengthen reporting as you scale.
Frequently Asked Questions (FAQs)
Role-based access control (RBAC) is a security model where permissions are grouped by job function, such as originator, servicer, or administrator, and users receive access by being assigned to a role rather than having permissions configured individually. In a mortgage servicing platform, this means a servicer can post payments and view loan history while an administrator can access system configuration, with each role seeing only what their job requires. The Mortgage Office implements RBAC through reusable permission groups that can be built once and applied instantly to any new user who shares that role.
Granular permission control allows administrators to enable or restrict specific actions, such as add, edit, post, or delete, at the individual module level, so a user can be permitted to view a loan file but blocked from deleting it. This goes beyond simple on/off access by letting administrators control each discrete capability within a module, such as allowing payment posting but preventing fee adjustments. In The Mortgage Office, permissions can be configured across every system from Loan Servicing to Trust Accounting, down to the individual task level.
The principle of least privilege means each user role is granted only the minimum permissions required to perform its specific tasks, no broader access than the job demands. In loan servicing, this translates to collectors being able to view account status and record notes without the ability to modify interest rates, and escrow analysts managing disbursements without access to core loan terms. Applying least-privilege access through role-based controls reduces the risk of accidental changes, unauthorized deletions, and insider fraud across sensitive loan records.
Setting up role-based access control starts with identifying the distinct job functions on your team, such as originators, servicers, and administrators, and mapping the specific modules and actions each role genuinely needs to perform its work. From there, you build a permission group for each role, configuring module and action access once, then assign each user to the appropriate group rather than configuring permissions account by account. In The Mortgage Office, this four-step process, define roles, build groups, assign users, monitor and adjust, means new hires can be granted correct access instantly without any per-user setup, but should an individual’s access differ from the standard permissions, adjustments can be made on a per user basis.
To restrict delete rights, administrators should configure role-based permissions to disable the delete action specifically for sensitive modules such as loan files, funding records, and payment history, while leaving view and edit rights intact for roles that need them. This prevents irreversible data loss from accidental or unauthorized deletions without blocking staff from performing their day-to-day work. The Mortgage Office allows administrators to turn delete rights on or off at the module level for any role or individual user, protecting the integrity of critical records.
When onboarding a new user, assign them to an existing permission group that matches their job function rather than configuring individual permissions for their account. Because role-based groups in The Mortgage Office are reusable, adding a user to the correct group instantly grants the full permission set defined for that role, no manual setup required. This approach eliminates configuration errors, speeds up time-to-productivity, and ensures the new user’s access is consistent with every other person in the same role.
When a team member changes roles, update their group assignment in the platform to immediately revoke their previous permissions and apply the access appropriate to their new function, no need to manually adjust individual settings. For departing employees, removing them from their assigned group or deactivating their account cuts off access across all modules at once, eliminating the orphaned-account risk that auditors commonly flag. The Mortgage Office allows administrators to adjust permissions at any time, so access always reflects current job responsibilities rather than accumulating from past roles.
An events journal is an immutable, built-in audit trail that records every transaction, edit, and change made across the platform database, capturing who performed each action and when. In mortgage servicing, this log is essential for audit readiness because it provides examiners, compliance teams, and supervisors with a verifiable record of every user action without relying on manual documentation. The Mortgage Office restricts events journal access to administrators and supervisors, ensuring the audit trail itself is protected from tampering by general users.
Data masking conceals sensitive fields, such as Tax Identification Numbers and Social Security Numbers, from users whose roles do not require access to that information, displaying the data as masked characters rather than the actual values. This limits PII exposure to only authorized roles without removing the data from the system or disrupting workflows for users who legitimately need it. In The Mortgage Office, TIN masking can be applied so that sensitive identifiers are visible only to users with explicit authorization, supporting GLBA privacy requirements and reducing insider-threat risk.
Assigning permissions user-by-user means configuring access individually for every account, which creates inconsistency, increases administrative overhead, and makes it difficult to audit who can do what across a large team. Role-based access control groups permissions into reusable roles so that access is defined once per job function and applied uniformly to every user in that group, reducing errors and scaling efficiently as teams grow or change. The Mortgage Office uses permission groups to eliminate per-user configuration entirely, so administrators manage access at the role level rather than account by account.
Separation of duties requires that no single user can both initiate and approve a sensitive transaction, for example, one role proposes a loan modification while a separate role with distinct permissions finalizes it. Role-based access control enforces this by ensuring conflicting permissions are never combined in a single user’s role assignment, preventing any one person from controlling an entire high-risk process end to end. This structure is a standard expectation of financial services examiners and reduces the opportunity for fraud or concealment of errors in payment posting, write-offs, and investor remittances.
Over-permissioned roles violate the principle of least privilege and expose sensitive loan data, borrower PII, and irreversible actions, such as deletions or fee adjustments, to users who have no legitimate need for them. This increases the risk of accidental changes, insider fraud, and data breaches, and creates audit findings when examiners discover that access rights exceed documented job responsibilities. Regularly reviewing role definitions against actual job functions and removing unnecessary permissions is the most effective way to close this gap before an audit or incident surfaces it.
Permission accumulation, often called privilege creep, happens when users are assigned to new roles without removing their previous group memberships, so their effective access grows with every job change rather than reflecting only their current responsibilities. In mortgage servicing environments with high staff turnover and frequent team reorganizations, this is one of the most common audit findings and a significant insider-fraud risk. Preventing it requires a disciplined joiner-mover-leaver process where role reassignment always includes removing the prior group assignment, and periodic access reviews confirm that each user’s permissions match their current job function.
The most effective approach is to design permission groups around real job functions, originator, servicer, administrator, rather than around system modules or individual exceptions, keeping the total number of groups proportional to the number of distinct roles on your team. Avoid creating new groups for one-off situations; instead, adjust an existing group’s permissions when a process changes, so the role catalog remains understandable and auditable over time. In The Mortgage Office, building groups once and assigning users to them, rather than layering exceptions, keeps the permission model clean, scalable, and easy to explain to examiners during compliance reviews.
Explore related knowledge
Access a wealth of resources to deepen your understanding of the lending industry. Our Knowledge Hub offers insights, tips, and best practices to help you navigate loan origination and servicing effectively.
Manual vs. Automated Loan Servicing: What Lenders Need to Know
The modern loan servicing landscape is complex.
Renovo’s CEO Kevin Werner Shares His Perspective on Scaling Loan Operations
In this short 3-minute video, Kevin Werner, CEO of Renovo Financial, shares insights from
7 Ways to Modernize Your Loan Programs: The TMO Playbook
Learn the strategies already trusted by more than 25 counties and a growing number of hous
Ready to power your business with The Mortgage Office?
Let us show you how efficient and accurate your loan management platform can be.