Access

Give people the work—not the whole warehouse

Define what a role can do, then decide where each team member can do it. Cybership keeps team authority, reusable job permissions, and warehouse access separate so a packing lead can run the Dallas floor without inheriting administration, deletion, or every building.

Build the role around the shift—not a vague job title

Packing Lead can view and run picking sessions and packing stations, read the totes, stock, and warehouse context those workflows need, and receive picked-batch notifications. Delete and team-administration access stay out of the role.

A MEMBER starts without broad authority. Assigning one or more custom roles creates an explicit permission union, so additional responsibility can be added without turning the person into an administrator.

Custom role

Packing Lead

Run pick-and-pack work at assigned warehouses without team administration or destructive access.

Assigned to · MEMBER
Permissions granted to the Packing Lead custom role
Base permissionsViewCreateDelete

Picking Sessions

READ_PICKING_SESSIONS

Granted: READ_PICKING_SESSIONS
Granted: WRITE_PICKING_SESSIONS
Not granted

Packing Stations

READ_PACKING_STATIONS

Granted: READ_PACKING_STATIONS
Granted: WRITE_PACKING_STATIONS
Not granted

Totes

READ_TOTES

Granted: READ_TOTES
Not granted
Not granted

Product Stock

READ_PRODUCT_STOCK

Granted: READ_PRODUCT_STOCK
Not granted
Not granted

Warehouses

READ_WAREHOUSES

Granted: READ_WAREHOUSES
Not granted
Not granted

Notification delivery

RECEIVE_PICKED_BATCH_NOTIFICATIONS

Enabled

Assign the job and the physical boundary together

The invitation carries three deliberate choices: MEMBER, the Packing Lead custom role, and DAL-01. When the invited person accepts, those choices become the member record operators can review in Team Members—without granting SEA-02 or every warehouse by implication.

The invitation records the selected custom role and validates the warehouse against Northline Supply. After acceptance, the member has the Packing Lead permission union plus an explicit DAL-01 warehouse assignment.

Invite team member

packing-lead@northline.example

Power role
MEMBER
Custom role
Packing Lead
Warehouse access

DAL-01

Dallas, TX

Invitation state
PENDING
MEMBER starts with no implicit permissions. Its assigned custom roles provide the permission union.

Invitation access summary

Review the member's starting scope before sending

Northline Supply
1Emailpacking-lead@northline.example
2Power roleMEMBER
3Custom rolePacking Lead
4Allowed warehouseDAL-01 · Dallas, TX
The invitation records the selected custom role and validates that DAL-01 belongs to Northline Supply.

After acceptance

The invitation becomes a reviewable Team Member record with the same power role, custom role, and warehouse assignment.

Team Members

Accepted invitation · Northline Supply

Active
MemberRoleAllowed Warehouses
PL

Packing Lead

packing-lead@northline.example

MEMBER
Packing Lead
DAL-01

Effective scope

Team
Northline Supply
Permissions
Packing Lead role union
Warehouse
DAL-01 only

MEMBER adds no implicit job permissions or warehouse access beyond these assignments.

For warehouse-aware work, check both the job and the building

When a Packing Lead scans a tote while building a multi-item picking cart, DAL-01 is the warehouse available in their normal product path. The tote lookup checks Read Totes and that warehouse before staging TOTE-DAL-014 for the next cart slot.

SEA-02 is absent from this member's selector. If a direct request still names SEA-02, the server rejects it before resolving a tote. Remove Read Totes and the next DAL-01 scan is denied too; move the member to AUS-01 and their available warehouse changes without rewriting Packing Lead.

Create Multi-Item Batch · Link totes

The normal DAL-01 product path beside one rejected direct request

Step 2 / 3

Visible product path

DAL-01 available
Current warehouseDAL-01 · Dallas, TXDAL-01 is the only warehouse available to this member; SEA-02 is absent from the selector.
Scanned tote barcodeTOTE-DAL-014

Read Totes

Granted

Warehouse access

DAL-01

Tote 14 staged · Cart 04 · Slot 1

The scan is staged in the form; the final batch creation persists the cart assignment.

1 / 8 staged

Direct request boundary

Rejected
Requested warehouseSEA-02 · Seattle, WAThis warehouse is not offered in the member's normal product selector.
Scanned tote barcodeTOTE-SEA-014

Read Totes

PASS

Warehouse access

DENY

Direct lookup rejected before tote resolution

You don't have access to warehouse. Please contact your administrator.

Change the source of access

Update the shared role when the job changes; update the member's warehouse set when only the physical assignment changes.

Update Packing Lead access

Change the reusable job grant and this member's warehouse set

Northline Supply

Role permissions

PermissionBeforeAfter

Packing Stations

READ_PACKING_STATIONS

Totes

READ_TOTES

Retained

READ_PACKING_STATIONS

Removed

READ_TOTES

Warehouse Access for Packing Lead

Remove

DAL-01

Allow

AUS-01

The member's available warehouse set now follows AUS-01. The Packing Lead role itself remains reusable for other assigned members.

Link totes · blocked on the next attempt

Missing permissions: Read Totes

Keep role ownership explicit

BLOCKED until every member and API key is unassigned

Least privilege that follows the work, not the org chart

The expensive access mistake is rarely a missing job title. It is a broad role that quietly bundles destructive actions, every warehouse, and unrelated alerts. Cybership separates team authority, job permissions, and physical warehouse scope so an operator can receive enough access to finish the shift without inheriting the whole operation.

separate team authority from job-specific roles
3 tiersOWNER and ADMIN receive team-wide authority; MEMBER receives only the union of explicitly assigned custom-role permissions
lets one person cover more than one assigned job
Role unionmany custom roles may be assigned to one member; the role picker presents the custom roles available to the current team
answer what the person may do and where
2 gatesa concrete warehouse operation must satisfy its declared permission and its explicit warehouse authorization boundary
can be reused across different warehouse assignments
1 rolechange the shared job permissions once, or move one member's physical scope without duplicating the entire role

Trusted by 3PLs and brands

2FLYcoAmmoSquaredAxion FulfillmentIndustry Thread Worksadrafül labs

See it in your operation

Bring us the role that keeps growing because no one trusts removing access

Show us the people, machine credentials, job boundaries, warehouse assignments, and alerts your team manages today. We’ll map team authority, reusable custom roles, and explicit warehouse scope against the work that actually happens.

No sales call is required to get sandbox access.

Continue exploring

View all features