Roles and permissions
Four roles, strictly ordered. Each level can do everything the levels below it can.
Who can do what
| Action | Viewer | Staff | Manager | Owner |
|---|---|---|---|---|
| Browse everything — dashboard, items, loans, people, labels | ✓ | ✓ | ✓ | ✓ |
| Check items out and in | — | ✓ | ✓ | ✓ |
| Add and edit people | — | ✓ | ✓ | ✓ |
| Mark items out of service / back in service | — | ✓ | ✓ | ✓ |
| Create, edit, retire, and restore items | — | — | ✓ | ✓ |
| CSV import | — | — | ✓ | ✓ |
| Settings — locations, categories, condition labels, item vocabulary | — | — | ✓ | ✓ |
| Full control of the organization | — | — | — | ✓ |
A useful mental model: viewers look, staff run the desk, managers own the inventory, the owner owns the account.
The owner manages accounts in Settings: invite someone by email (they get a link, good for 7 days, to choose their own password), change their role, or deactivate them — deactivation ends their access immediately and is reversible. Two guardrails: you can't change your own role or deactivate yourself, and every organization keeps at least one owner.
Borrowers are not accounts — they're directory entries and never sign in.
Sessions and safety
Sign-ins last 12 hours in a signed, HTTP-only cookie. Every action that changes data is CSRF-protected, and every request is scoped to your organization — there is no way to address another organization's data from the app.
The audit trail
Every change — item created or edited, person added, checkout, check-in, out-of-service, retire, import — is recorded in an append-only log: who did it, when, and the before and after values. Audit entries are never edited or deleted. The dashboard shows the latest 15 as Recent activity.
Next: Multi-location