RTX5 RBAC
Authorization is enforced on the server. Hiding a button is not an access-control boundary.
Specified for RTX5 broker deployments. Not evidence that a named production build has passed acceptance tests.
Main capabilities
Server-side authorization
Every command is checked, including API paths.
Object-level authorization
Another tenant's identifiers must fail.
MFA
MFA and expiring sessions for privileged operators.
How it works
- 01
Authenticate
A principal acts inside a tenant and account scope.
- 02
Validate
Pre-trade risk and instrument rules run first.
- 03
Record
A durable journal feeds positions, ledger and audit.
- 04
Operate
Managers and APIs use the same permission-enforced path.
Technical details
Server authority
The client is a user interface. Entitlement, order and risk decisions remain on the server.
No inferred venues
Listing a category does not establish venue, data or regulatory access.
Security and controls
Authorization
Tenant, object and function checks are enforced server-side.
Frequently asked questions
Is this live today?
Specified for RTX5 broker deployments. Not evidence that a named production build has passed acceptance tests.
Can I get a quote?
Yes. Use Request a Quote on the contacts page.