In our last post, we introduced Workspaces, the secure home where a business manages its money in Lisk. But a workspace on its own doesn't move money or approve payments. People do. That's where Profiles come in.
If Workspaces answer "where does my business operate?", Profiles answer "who, specifically, is doing what inside it?" For any finance team, that second question is just as important as the first, because it's the difference between a system you can trust and one you can't audit.
What a Profile Is
A profile is the individual identity for each person using Lisk. It's the record that logs in, belongs to a workspace, and carries a name, email, photo, and set of security settings. Once someone is part of a workspace, their profile is what gets assigned a role, given access to specific accounts or portfolios, and named as the actor behind any action they take.
Profile, Member, and Workspace: How They Relate
A few related terms are worth untangling, since Lisk uses each one deliberately:
A profile is your identity as a person on Lisk, independent of any one workspace.
A member is that same profile in the context of a specific workspace, meaning a profile that has joined it. So if you're part of your company's workspace on Lisk, you have a profile, and you are a member of that workspace. The distinction matters because your identity as a person is separate from your relationship to any single business.
A workspace, by contrast, is the operating environment itself: the company or team context that contains members, accounts, settings, roles, and financial resources. A profile is simply one of the people who can access that environment, depending on their permissions. When a profile initiates a payment, that single action has three parts: an actor (the profile), a context (the workspace), and a source of funds (the account). Keeping those three separate is what makes every action in Lisk traceable.
What's Inside a Profile
A profile carries a photo or avatar, a name, an email address, and a role. In the interface, Lisk typically surfaces a team member's photo and full name.
Profiles also connect to your security setup such as two-factor authentication, passkey-based transaction signing, and your recovery phrase. Admins and owners can see some of this security status for members of their workspace, too. None of this is cosmetic. Your profile settings are directly tied to how secure your workspace's financial operations actually are.
You might notice that profiles don't have usernames. They operate off your name and email instead. That's different from workspaces, which do have usernames used for identity and on-platform addressing. This design choice is intentional: a profile is a private, internal identity used for access and attribution, not a public payment handle.
Profiles Are Private, and the Wallet Stays Hidden
Profiles are visible only within the workspace context where they're relevant, not as a public Lisk identity. Workspaces will represent businesses publicly over time; profiles represent the people inside those businesses, privately.
Underneath every profile sits wallet and signing infrastructure, but Lisk deliberately keeps it out of view. A profile isn't meant to feel like a crypto wallet, and current product guidance is explicit that team member wallets shouldn't hold workspace funds and wallet details shouldn't surface in the normal user experience. The wallet infrastructure exists purely to handle secure authorization and signing in the background. For a finance team, this means your people interact with names, roles, and permissions, not addresses and keys.
That signing capability, though, is very real. A user can only approve certain financial actions if their profile has the required setup: the web app is where you manage the workspace day to day, while approvals and signing happen exclusively on mobile through passkeys. In other words, a profile isn't just a login. It's the named human actor standing behind every approval.
Roles: What a Profile Can Do in a Workspace
Every profile that joins a workspace is assigned one of three roles:
- Owner is the highest-authority profile in a workspace. Owners can transfer ownership, delete the workspace, and have all other capabilities admins have as well. There is exactly one owner per workspace.
- Admin has broad operational control: managing settings, members, resources, and day-to-day workspace operations.
- Member has more limited access, scoped to the resources they've specifically been assigned and the actions their resource-level permissions allow.
Resource-Level Access: A Second Layer of Control
On top of a workspace role, a profile can also be granted specific access to individual resources, like accounts or portfolios. A profile might be a member of the workspace, an approver on one account, a viewer on another, and have no access at all to a third. This lets a business assign access precisely instead of giving every team member visibility into everything.
For accounts specifically, current access levels are:
- Approver, who can act on an account according to its approval policy, including initiating or approving financial actions.
- Viewer, who has read-only access to relevant account and transaction information but cannot take financial actions.
That distinction lets a finance team give someone visibility into the numbers without also giving them the ability to move money, which is exactly the kind of separation of duties most finance teams already expect from any serious financial system.
How Profiles Join, and How They Leave
New people join a workspace through an email invitation. That email becomes the basis for their profile and their workspace membership. By default, invitees join as members; any higher authority, like admin access, has to be granted separately through the appropriate permission process. That extra step is a deliberate safeguard, so no one lands in a sensitive role by default.
When someone leaves a business, Lisk deactivates their profile rather than deleting it. Deleting the person would break the historical record. Deactivation means the person loses workspace access going forward, but their past actions stay attributed to them, and they still appear correctly in historical transactions, approvals, notes, attachments, and audit logs. History has to remain intact, even after someone is gone.
Why This Matters: Accountability
Every important action inside Lisk, from a transaction approval to an admin change to a resource access update, needs to be tied to a named person, and the profile is what provides that identity. Put simply:
Profiles make financial operations accountable by tying every action to a named person.
That accountability also extends into notifications, because notifications are targeted based on a profile's relationship to a specific event (as the person who initiated a transaction, an approver on it, a cardholder, or an admin), so the right person hears about the right thing, rather than everyone getting everything.
The Bottom Line
If a workspace is the company environment, and accounts are where the money sits, profiles are the people who operate that environment under controlled permissions. They connect a real person to their workspace membership, their role, their resource access, their signing capability, their notifications, and their audit history.
For a founder or finance lead evaluating Lisk, that's the real promise of profiles: every payment, every approval, and every admin change in your workspace is tied to a named, identifiable person, not an anonymous wallet address. That's what makes team-based finance auditable.