Give people the work—not the whole warehouse
Build the role around the shift—not a vague job title
Packing Lead can view and run picking sessions and packing stations, read the totes, stock, and warehouse context those workflows need, and receive picked-batch notifications. Delete and team-administration access stay out of the role.
A MEMBER starts without broad authority. Assigning one or more custom roles creates an explicit permission union, so additional responsibility can be added without turning the person into an administrator.
Custom role
Packing Lead
Run pick-and-pack work at assigned warehouses without team administration or destructive access.
| Base permissions | View | Create | Delete |
|---|---|---|---|
Picking Sessions READ_PICKING_SESSIONS | Granted: READ_PICKING_SESSIONS | Granted: WRITE_PICKING_SESSIONS | Not granted |
Packing Stations READ_PACKING_STATIONS | Granted: READ_PACKING_STATIONS | Granted: WRITE_PACKING_STATIONS | Not granted |
Totes READ_TOTES | Granted: READ_TOTES | Not granted | Not granted |
Product Stock READ_PRODUCT_STOCK | Granted: READ_PRODUCT_STOCK | Not granted | Not granted |
Warehouses READ_WAREHOUSES | Granted: READ_WAREHOUSES | Not granted | Not granted |
Notification delivery
RECEIVE_PICKED_BATCH_NOTIFICATIONS
Assign the job and the physical boundary together
The invitation carries three deliberate choices: MEMBER, the Packing Lead custom role, and DAL-01. When the invited person accepts, those choices become the member record operators can review in Team Members—without granting SEA-02 or every warehouse by implication.
The invitation records the selected custom role and validates the warehouse against Northline Supply. After acceptance, the member has the Packing Lead permission union plus an explicit DAL-01 warehouse assignment.
Invite team member
packing-lead@northline.example
DAL-01
Dallas, TX
Invitation access summary
Review the member's starting scope before sending
After acceptance
The invitation becomes a reviewable Team Member record with the same power role, custom role, and warehouse assignment.
Team Members
Accepted invitation · Northline Supply
| Member | Role | Allowed Warehouses |
|---|---|---|
PL Packing Lead packing-lead@northline.example | MEMBER Packing Lead | DAL-01 |
Effective scope
MEMBER adds no implicit job permissions or warehouse access beyond these assignments.
For warehouse-aware work, check both the job and the building
When a Packing Lead scans a tote while building a multi-item picking cart, DAL-01 is the warehouse available in their normal product path. The tote lookup checks Read Totes and that warehouse before staging TOTE-DAL-014 for the next cart slot.
SEA-02 is absent from this member's selector. If a direct request still names SEA-02, the server rejects it before resolving a tote. Remove Read Totes and the next DAL-01 scan is denied too; move the member to AUS-01 and their available warehouse changes without rewriting Packing Lead.
Create Multi-Item Batch · Link totes
The normal DAL-01 product path beside one rejected direct request
Visible product path
Read Totes
Granted
Warehouse access
DAL-01
Tote 14 staged · Cart 04 · Slot 1
The scan is staged in the form; the final batch creation persists the cart assignment.
Direct request boundary
Read Totes
PASS
Warehouse access
DENY
Direct lookup rejected before tote resolution
You don't have access to warehouse. Please contact your administrator.
Change the source of access
Update the shared role when the job changes; update the member's warehouse set when only the physical assignment changes.
Update Packing Lead access
Change the reusable job grant and this member's warehouse set
Role permissions
Packing Stations
READ_PACKING_STATIONS
Totes
READ_TOTES
Retained
READ_PACKING_STATIONS
Removed
READ_TOTES
Warehouse Access for Packing Lead
Remove
DAL-01
Allow
AUS-01
The member's available warehouse set now follows AUS-01. The Packing Lead role itself remains reusable for other assigned members.
Link totes · blocked on the next attempt
Missing permissions: Read Totes
Keep role ownership explicit
BLOCKED until every member and API key is unassigned
Least privilege that follows the work, not the org chart
The expensive access mistake is rarely a missing job title. It is a broad role that quietly bundles destructive actions, every warehouse, and unrelated alerts. Cybership separates team authority, job permissions, and physical warehouse scope so an operator can receive enough access to finish the shift without inheriting the whole operation.
- separate team authority from job-specific roles
- 3 tiersOWNER and ADMIN receive team-wide authority; MEMBER receives only the union of explicitly assigned custom-role permissions
- lets one person cover more than one assigned job
- Role unionmany custom roles may be assigned to one member; the role picker presents the custom roles available to the current team
- answer what the person may do and where
- 2 gatesa concrete warehouse operation must satisfy its declared permission and its explicit warehouse authorization boundary
- can be reused across different warehouse assignments
- 1 rolechange the shared job permissions once, or move one member's physical scope without duplicating the entire role
See it in your operation
Bring us the role that keeps growing because no one trusts removing access
Show us the people, machine credentials, job boundaries, warehouse assignments, and alerts your team manages today. We’ll map team authority, reusable custom roles, and explicit warehouse scope against the work that actually happens.
No sales call is required to get sandbox access.
Continue exploring
Related workflows
Warehouse Configuration
Operations
Define warehouse origins and local time, then inherit operating settings until a site needs an override.
Audit Logs
Platform
Investigate operational changes beside the order, inventory movement, return, delivery, rule, or file job that produced them.
API Keys
Access
Issue named integration credentials, compose member access from roles, and disable one connection at a time.
Client Management
3PL
Run each 3PL client from one roster, with channels, pricing, operating rules, fulfillment state, and deliberate offboarding.