Roles & permissions
AnchorVault has four roles. They exist so a rigger can log an inspection without being able to rewrite what an inspection means, and so an auditor can read every record without being able to touch one. Roles are per team, and unlimited people can hold one — you are never charged for a seat.
Set from the Team screen. Only an admin (or the organization owner) can change somebody's role.
Full control, including members, roles and inspection templates. Every team needs at least one — the app will not let you demote the last one.
Manage gear and inspections, including deleting assets and managing categories. Cannot change members or publish templates.
Add gear and log inspections. Cannot delete. The right role for most of a crew.
Read and export only. Cannot change anything, on any screen. Built for auditors, clients and safety officers who need the evidence but should never be able to edit it.
These are the app’s own permission rules, row for row — not a simplified summary. They are held against the code by a test, so this table cannot quietly drift from what the app actually enforces.
| Capability | Admin | Manager | Member | Viewer |
|---|---|---|---|---|
| View gear, schedule & reports | Yes | Yes | Yes | Yes |
| Export reports & spreadsheets | Yes | Yes | Yes | Yes |
| Add & edit assets | Yes | Yes | Yes | No |
| Log inspections & notes | Yes | Yes | Yes | No |
| Attach documents | Yes | Yes | Yes | No |
| Delete assets | Yes | Yes | No | No |
| Remove documents | Yes | Yes | No | No |
| Manage categories | Yes | Yes | No | No |
| Publish inspection templates | Yes | No | No | No |
| Edit Tag ID | Yes | No | No | No |
| Edit reminder settings | Yes | No | No | No |
| Delete history entries | Yes | No | No | No |
| Manage team & roles | Yes | No | No | No |
Swipe the table sideways for the rest of the roles.
Publishing a template is admin-only on purpose. A template decides what "inspected" means for everyone and what every future compliance report says, so it sits a step above managing the gear itself.
On a multi-team account, the owner sits above every team rather than joining each one. They can create teams, rename them, set roles and remove people anywhere under the organization — without taking up a place on any roster. It is not a role you assign; it is whoever owns the account.
Whether someone may sign as the competent person is a separate switch an admin grants per person. A rigger can be the competent inspector without being handed team management and template publishing — and an admin who isn't qualified doesn't become one by being an admin.
Working on your own? A solo or personal account has no roles and no team screen at all — there is nobody to have a role relative to. Roles appear the moment your plan allows a second person.
Coming soon
Every paid plan carries unlimited users, whatever role they hold. Add the whole crew, the safety manager and the auditor who reads once a year — the bill never moves.
Request early access