TrustElevate Authorisation Dashboard
Meridian Facilities Group

Business authorisation dashboard

Each role sees only what it needs. A finance lead approves spend, compliance audits the trail, IT sees system health, not who paid whom.

Active mandates
2
Covering 4 operations agents
Awaiting your approval
1
Above sub-delegation threshold
This month, in scope
£4,858.50
of £33,000 combined ceiling
Next mandate expiry
31 Mar 2027
Office Supplies

Awaiting your approval

Sub-delegation above threshold: Reliant HVAC Services

The Facilities Maintenance operations agent has requested to sub-delegate a £3,200.00 emergency contractor payment, above the £2,000 threshold that requires your explicit sign-off. Requested 2 hours ago.

Decision recorded and sent to the operations agent.

Mandates

Office Supplies, approved vendorsActive
Ceiling
£8,000.00 / mo
Vendors
6 approved
Expires
31 Mar 2027
Facilities Maintenance ContractsActive
Ceiling
£25,000.00 / qtr
Vendors
4 approved
Expires
30 Jun 2027

Transactions & audit trail

DORA Art. 30
Date & timeSupplierAmountMandateStatus
22 Aug 2026, 11:20Crestline Office Supplies£412.50Office SuppliesCompleted
21 Aug 2026, 14:05Reliant HVAC Services£3,200.00Facilities MaintenancePending approval
20 Aug 2026, 09:40Bright Print Co.£96.00Office SuppliesCompleted
18 Aug 2026, 15:12Reliant HVAC Services£1,150.00Facilities MaintenanceCompleted

Compliance & retention

Records are retained for a minimum of five years from the transaction date under the EU AML Regulation. This entry reflects the Register of Information Mastercard maintains on TrustElevate as an ICT third-party provider under DORA.

Register of Information
Function: agent identity & mandate orchestration. Criticality: important function. Last reported: 3 Aug 2026.
Audit & inspection access
Unrestricted access for Mastercard and their competent authority, per DORA Article 30.

This is a design mockup for pilot discussion, not a compliance certification. It illustrates how TrustElevate's authorisation dashboard is being built to address specific obligations under GDPR, DORA, the EU AML Regulation, and the Cyber Resilience Act, each element above is tagged to the requirement it responds to. Several of the underlying obligations, including a completed DPIA, a Register of Processing Activities, and a formal DORA Register of Information entry, are organisational work not yet finished, and are not represented as done by this mockup.