RTX5 RBAC

Authorization is enforced on the server. Hiding a button is not an access-control boundary.

Specified for RTX5 broker deployments. Not evidence that a named production build has passed acceptance tests.

Main capabilities

Server-side authorization

Every command is checked, including API paths.

Object-level authorization

Another tenant's identifiers must fail.

MFA

MFA and expiring sessions for privileged operators.

How it works

  1. 01

    Authenticate

    A principal acts inside a tenant and account scope.

  2. 02

    Validate

    Pre-trade risk and instrument rules run first.

  3. 03

    Record

    A durable journal feeds positions, ledger and audit.

  4. 04

    Operate

    Managers and APIs use the same permission-enforced path.

Technical details

Server authority

The client is a user interface. Entitlement, order and risk decisions remain on the server.

No inferred venues

Listing a category does not establish venue, data or regulatory access.

Security and controls

Authorization

Tenant, object and function checks are enforced server-side.

Frequently asked questions

Is this live today?

Specified for RTX5 broker deployments. Not evidence that a named production build has passed acceptance tests.

Can I get a quote?

Yes. Use Request a Quote on the contacts page.

Continue evaluating RTX5