Document Management & Security in MCA Servicing
MCA document management is the secure storage, organization, and controlled sharing of the files tied to a merchant cash advance — applications, bank statements, contracts, and syndication agreements. Access to each file is governed by a security level so the right parties see the right documents. In MCA Track, every merchant has a secure file vault, and documents exist at both the lead and merchant level.
Key takeaways
- Each merchant has a secure file vault for storing, organizing, and sharing account files; documents exist at both the lead and merchant level.
- Access is governed by three security levels: All, Underwriter, and Specific Users.
- Role-based visibility means funder admins see everything, while ISO and merchant-portal users see only what is shared with them.
- Files can be uploaded individually or in bulk, viewed inline or downloaded, and deleted with permission.
- Lead document types feed the readiness check when converting a lead to a merchant.
What is MCA document management in MCA Track?
MCA document management in MCA Track is a secure file vault attached to each merchant for storing, organizing, and sharing account files. Documents exist at both the lead and merchant level, and access to each file is governed by a security level. The merchant page shows a document-count badge, and funder admins also see documents attached to the lead that became the merchant.
Files carry a description, tags, and a security level. You can upload individually or via the bulk upload page, view inline or download, and delete with the right permission — deleting removes both the record and the stored file.
What security levels control document access?
MCA Track uses three document security levels that determine who can see each file. The level is set per document, so a single merchant vault can mix freely shared files with underwriter-only and individually restricted ones.
| Security level | Who can see it |
|---|---|
| All | Any authenticated user with access to that merchant — funder, ISO, and merchant-portal users. |
| Underwriter | Funder admins and underwriters only, plus anyone explicitly granted access. |
| Specific Users | Only individually named users — used for sensitive or syndicator-specific files. |
How does role-based visibility work?
Role-based visibility layers on top of the security level to decide what each user can actually open. Funder admins see everything. Underwriters see All and Underwriter documents plus any Specific-Users files shared with them. Funder users and sales reps see only All-level files.
ISO users see only what is shared with them, unless their ISO syndicates on the deal and has view-all enabled. Merchant-portal users see only files shared with them. This keeps sensitive underwriting and syndicator documents restricted while still letting partners access the files they need.
How do you upload and manage documents?
Documents are managed from the merchant’s Documents list, where each file shows its description, tags, security level, and available actions. A typical flow is:
- Open the merchant’s Documents list, where every file appears with its description, tags, and security level.
- Add files with New Document for a single upload, or use the bulk upload page for many at once.
- Set each file’s description, tags, and security level (All, Underwriter, or Specific Users).
- View a file inline or download it as needed.
- Delete a file with permission — this removes both the record and the stored file.
At the lead stage, document types such as Bank Statement, Application, Contract, and custom types feed the readiness check when converting a lead to a merchant. To see where documents fit in the broader flow, review how a lead is converted and funded into a merchant and how leads move through the pipeline. Visibility ties directly to MCA Track’s user roles and permissions, and the full picture lives in the MCA Track servicing guide.
Want to see secure document controls applied to your own deals? Book a walkthrough →
Frequently asked questions
MCA Track supports three security levels: All, which any authenticated user with access to the merchant can see; Underwriter, limited to funder admins and underwriters plus anyone granted access; and Specific Users, visible only to individually named users.
No. ISO users see only what is shared with them, unless their ISO syndicates on the deal and has view-all enabled. Merchant-portal users see only files shared with them.
Yes. You can upload files individually with New Document or use the bulk upload page to add many at once. Files can then be viewed inline or downloaded.
Deleting a document requires permission and removes both the record and the stored file.