Skip to main content

Roles & Permissions

Stockaj uses a role-based access control system to manage what each team member can do in your workspace.

Roles

Each user in a workspace is assigned exactly one role:

RoleDescription
OwnerFull access to everything, including billing and workspace deletion
AdminFull access except billing management
EditorCan manage items, rentals, and renters (create, edit, delete)
CreatorCan view and create items, rentals, and renters (limited edit)
GuestView-only access to items, rentals, and renters

Managing Roles

Navigate to Settings → Users & Roles to view and change user roles.

Screenshot needed

screenshot-roles-management.png — The roles management page showing users with their assigned roles.

Permissions Detail

Owner

AreaPermissions
ItemsView, Create, Edit, Delete, Restore
Serial NumbersView, Manage
RentersView, Create, Edit, Delete, Restore
RentalsView, Create, Edit, Delete, Assign, Export
TagsView, Create, Edit, Delete, Restore
QR CodesGenerate, Scan, Download
UsersManage
AlertsView, Manage, Acknowledge
WebhooksView, Create, Edit, Delete
SettingsView, Manage
BillingManage

Admin

Same as Owner, except:

  • ❌ Cannot manage billing/subscription

Editor

AreaPermissions
ItemsView, Create, Edit, Delete, Restore
Serial NumbersView, Manage
RentersView, Create, Edit, Delete, Restore
RentalsView, Create, Edit, Delete, Export
TagsView, Create, Edit, Delete
QR CodesGenerate, Scan, Download
AlertsView, Acknowledge

Creator

AreaPermissions
ItemsView, Create, Edit
Serial NumbersView, Manage
RentersView, Create, Edit
RentalsView, Create, Edit
TagsView, Create
QR CodesGenerate, Scan
AlertsView, Acknowledge

Guest

AreaPermissions
ItemsView
Serial NumbersView
RentersView
RentalsView
TagsView
QR CodesScan
AlertsView

Custom Roles

Workspace owners can customize role permissions under Settings → Roles to fine-tune access for their team.

Screenshot needed

screenshot-custom-roles.png — The custom roles configuration page.

tip

Follow the principle of least privilege — give each team member only the permissions they need to do their job.