Roles and permissions

Four roles, strictly ordered. Each level can do everything the levels below it can.

Who can do what

ActionViewerStaffManagerOwner
Browse everything — dashboard, items, loans, people, labels ✓✓✓✓
Check items out and in —✓✓✓
Add and edit people —✓✓✓
Mark items out of service / back in service —✓✓✓
Create, edit, retire, and restore items ——✓✓
CSV import ——✓✓
Settings — locations, categories, condition labels, item vocabulary ——✓✓
Full control of the organization ———✓

A useful mental model: viewers look, staff run the desk, managers own the inventory, the owner owns the account.

The owner manages accounts in Settings: invite someone by email (they get a link, good for 7 days, to choose their own password), change their role, or deactivate them — deactivation ends their access immediately and is reversible. Two guardrails: you can't change your own role or deactivate yourself, and every organization keeps at least one owner.

Borrowers are not accounts — they're directory entries and never sign in.

Sessions and safety

Sign-ins last 12 hours in a signed, HTTP-only cookie. Every action that changes data is CSRF-protected, and every request is scoped to your organization — there is no way to address another organization's data from the app.

The audit trail

Every change — item created or edited, person added, checkout, check-in, out-of-service, retire, import — is recorded in an append-only log: who did it, when, and the before and after values. Audit entries are never edited or deleted. The dashboard shows the latest 15 as Recent activity.

Next: Multi-location