Who can do what
This is the permissions matrix for Carrier Stash’s three roles: User, Library Owner, and Org Admin. Two ground rules apply to every row. First, doing anything in a library requires being assigned to that library — Org Admins are the one exception, and can act in every library of their organization. Second, the access mode changes what you can see, never what you can do. And one thing that surprises people: Library Owners do not manage who is assigned to their library — assignments are Org Admin only.
Permissions matrix
| Action | User | Library Owner | Org Admin |
|---|---|---|---|
| Check out a carrier | ✅ | ✅ | ✅ |
| Check in a carrier | ✅ | ✅ | ✅ |
| Renew a loan | ✅ ¹ | ✅ ¹ | ✅ ¹ |
| Quick-create a caregiver at check-out | ✅ | ✅ | ✅ |
| Create or edit a caregiver | ✅ | ✅ | ✅ |
| Add, amend, or clear caregiver flags | ❌ | ✅ | ✅ |
| Override a Do Not Lend block | ❌ | ✅ ² | ✅ ² |
| Record a waiver attestation | ✅ | ✅ | ✅ |
| Record a fit check | ✅ | ✅ | ✅ |
| Add a carrier | ❌ | ✅ ³ | ✅ ³ |
| Edit a carrier | ❌ | ✅ | ✅ |
| Change a carrier’s status (e.g. Out for Repair) | ❌ | ✅ | ✅ |
| Archive a carrier | ❌ | ✅ | ✅ |
| Give a carrier away | ❌ | ✅ | ✅ |
| Start a permanent delete | ❌ | ✅ ⁴ | ❌ ⁴ |
| Cancel a pending delete | ❌ | ✅ ⁴ | ✅ ⁴ |
| Transfer a carrier between libraries | ❌ | ✅ ⁵ | ✅ |
| Bulk import (carriers, caregivers) | ❌ | ✅ ³ ⁶ | ✅ ³ |
| Add, notify, or remove waitlist entries | ✅ ⁷ | ✅ ⁷ | ✅ ⁷ |
| Reserve a carrier | ✅ | ✅ | ✅ |
| Create events and packing lists | ✅ ⁸ ⁹ | ✅ ⁹ | ✅ ⁹ |
| Advance packing-list stages | ✅ ¹⁰ | ✅ | ✅ |
| Mark carriers packed or returned | ✅ | ✅ | ✅ |
| Manage library assignments | ❌ | ❌ | ✅ |
| Invite people to the organization | ❌ | ❌ | ✅ |
| Change billing | ❌ | ❌ | ✅ |
| Anonymize a caregiver | ❌ | ❌ | ✅ |
Role footnotes
These footnotes are about who you are — no plan changes them.
- ² An override needs a typed reason and is recorded on the loan and in the audit log. A Library Owner can only override in a library they own. See What the Do Not Lend gate does.
- ⁴ A permanent delete is started by a Library Owner of the carrier’s library — deliberately, an Org Admin can’t start one. It then waits in a 24-hour cooling-off window, during which any Library Owner of that library or any Org Admin can cancel it.
- ⁵ A transfer is started by a Library Owner of the library the carrier is currently in (or an Org Admin). No permission is needed in the destination library.
- ⁶ Importing carriers needs Library Owner in the library being imported into; importing caregivers needs Library Owner in any library of the organization.
- ⁸ A User can’t create the event itself — that needs a Library Owner or Org Admin — but once an event exists, any member can create a packing list under it.
- ¹⁰ A User can advance the stages of a packing list they own or created. Advancing someone else’s list needs a Library Owner or Org Admin.
Tier footnotes
These footnotes are about your organization’s plan — no role bypasses them. See Subscription tiers, limits, and soft lock.
- ¹ Renewals are part of the Starter plan and above, for every role. Check-in is never tier-gated.
- ³ Adding or importing carriers is also subject to the plan’s active-carrier cap, whatever your role.
- ⁷ Adding waitlist entries needs Starter or above; removing entries is never gated, so a downgraded organization can wind its waitlists down.
- ⁹ Creating events and packing lists needs Starter or above; existing events stay readable and closable after a downgrade.
- Not in the table: the Reports workspace is a Pro-and-above feature. That’s a tier gate, not a role gate — any member who can see the underlying data can use it.
See also
Last updated on