Intermediaries and affiliations
An intermediary is a legal organisation that participates in the lending process. A user's affiliation links the account to that intermediary and supplies the scope for partner-restricted saved queries.
Keep organisation, context, and permission separate. The intermediary describes the partner. The affiliation identifies which partner the user represents. Active permission groups determine what the user can do.
- For
- Access administrators maintaining partner organisations and affiliations.
- Requires
- Intermediary, user, group, and affiliation permissions needed for the intended change.
- Available when
- The organisation uses intermediaries or Partner-restricted saved queries.
- Before you begin
- Confirm the legal organisation, affected users, required groups, and expected in-scope records.
- Expected result
- The intermediary has the intended users and groups, and representative users see only the correct partner scope.
How intermediary access fits together
| Part | Meaning | Does not do by itself |
|---|---|---|
| Intermediary | The partner's legal-organisation entry. | Create a login or expose applications. |
| Affiliation | The intermediary context associated with a user and used for applicable partner scoping. | Grant application, loan, query, or administration permission. |
| User | The individual or API identity that signs in. | Define the partner organisation or its complete access. |
| Permission group | Operations granted to its active users and associated intermediary members. | Restrict a list to the current affiliation unless the applicable partner-query control also applies. |
For a new application started by an affiliated user, Finsaku sets the current affiliation as Seller and Submitter. Partner application-query scoping compares the current affiliation with Submitter. This does not create equivalent scoping for loans, payments, or every direct link.
Create an intermediary
- Open Administration → Add Intermediary.
- Enter the organisation's legal-person identity, registration, contact, address, and configured fields.
- Under Login, select any initial Groups when permitted.
- Select Add.
- Open the saved intermediary and confirm its details, users, and groups.
Use one intermediary per real partner organisation. Do not combine unrelated partners into a general bucket because affiliation is used as an access and reporting boundary.
Assign an existing user
- Open the intermediary.
- In Users, select Assign.
- Search for an active user without an existing intermediary affiliation.
- Select the user and confirm that it appears in the table.
Finsaku prevents selecting a user that is already affiliated with another intermediary. Remove the old association only after confirming that the move is correct and reviewing its visibility impact.
Select Create in the Users section to create a new user with this affiliation preselected.
Assign a permission group
- In the intermediary's Groups section, select Assign.
- Choose a group that is not already associated.
- Confirm the group's status and permissions.
You can also select Create to create a new group with the intermediary as an initial member. Removing the group association does not delete the group or its other members.
Partner visibility
For a Loan Application saved query, a user with List Partner Queries and without List Internal Queries receives an automatic condition that matches the current affiliation to the application's Submitter. The query must also use Partner visibility.
This automatic affiliation condition does not establish partner scope for Loans, Payments, or every other record type. Use Distribute lending through intermediaries to configure and test the complete application channel.
Test the intermediary's users against:
- Workspace lists and list totals;
- global search;
- direct record links;
- related lists embedded in people or applications;
- exports;
- bulk assignment and assignee choices.
Do not assume a partner restriction is correct because the intended list appears. Verify that an unrelated record does not appear and cannot be opened.
Change or remove an affiliation
Removing a user from the intermediary clears that association; it does not block or delete the user. Before moving a user:
- record the approved new affiliation;
- check outstanding assigned applications or loans;
- remove the old association;
- assign the new intermediary;
- have the user refresh or sign in again;
- test searches, lists, direct links, and exports.
Changing an intermediary's displayed details does not rewrite earlier exported files or documents.
Troubleshooting
| Symptom | Check |
|---|---|
| User cannot be assigned | The user is active and does not already have an intermediary affiliation. |
| Partner user sees no records | User affiliation, active groups, permissions, Partner query conditions, and actual record affiliation. |
| Partner user sees too many records | Query visibility and conditions, direct-record permissions, embedded queries, and other group memberships. |
| Group is not available | Group status, existing association, and the administrator's list/assign permissions. |
| Removing an association did not block login | Affiliation and account status are separate; block the user when login must stop. |
Use Distribute lending through intermediaries for the end-to-end setup, Saved queries to configure partner-visible lists, and Users to maintain individual accounts.