Access to a business is a membership that holds one or more roles, and a role is a set of permissions.

Permissions are named after what they do

Each is a specific action: submitting verification, connecting a bank, removing a team member. A role is a chosen set of them, which is why two businesses can both have a role called “Accountant” that means different things.

Enforced by Paynecta, not by the screen

If your role does not cover something, the button is not there. That is a convenience, not the protection: the request is refused by Paynecta itself whether or not a button exists.
This matters if you ever automate against Paynecta. There is no action available by constructing a request that would not be available by clicking.

Owners hold everything, including what does not exist yet

The owner role has no fixed list of permissions. It holds whatever Paynecta can do, so when a new part of the product ships, owners can use it on day one rather than being locked out of it until someone edits their role.

You cannot reach another business by guessing

Every request naming a business is checked against your membership of that specific business. An identifier belonging to someone else does not resolve for you, and Paynecta answers as though it does not exist rather than confirming that it does.