Doors and keys — who can open what
Every part of a boat's record sits behind a door. Each person holds the keys their role gives, plus any the owner — or a manager, for keys they hold — adds or takes away.
theONE keeps the boat's record behind doors — Systems & engines, Work orders, Money, Documents, Trips & legs, Crew & guest cards and the rest. Each door has a lock for seeing and one or more for changing, and each lock takes a key. Your role gives you a starting set of keys. The owner can give one person an extra key or take one away; a manager can do the same for keys they hold themselves, for people below manager. Nobody changes the owner's keys. The cloud checks the keys on every record it sends and every change it takes, and the app reads the same keys twice: a screen hides or greys out what you hold no key for and says which key in one line, and the app's own record refuses a change without the key before it is saved or sent. So a screen does not offer what the cloud would refuse. A change takes effect in the cloud at once and is written to the audit log. When a key is taken away, the phone takes off it what that key opened the next time it hears from the cloud, and says what it removed and why. One limit, said plainly: the cloud cannot take back what a phone holds while it is off the network. It keeps its copy until it next connects, and after a day without the cloud it makes only the changes its role's own keys allow.
Steps
-
Open someone's keys
Menu (☰) → Settings → Member Users. Under On this boat in the cloud, tap Keys on the person's row. Keys shows only when you may change that person's keys: the owner sees it for everyone who is not an owner; a manager, or a captain who is also the manager, for people below manager. Captains, crew, vendors and guests change no keys.
-
Read the list
Each key is listed under its door, in plain words. Their role's default means the role gives it. Given and Taken away say who changed it and, for a key given for a set time, until when; Opens says when a key is narrower than the whole door: their own only; the ones assigned to them; their trip only; from trips they were on, and their own. A switch you can't move is a key you don't hold yourself, or one only the owner gives — Money, Documents, everyone's crew and guest cards, signing off vendor work, the web portal and giving keys.
-
Give, take away, or put back
Switch a key on to give it and off to take it away. Back to default ends whatever was changed and returns the key to what their role gives. To give a key for a set time, switch on Give for a set time and pick the date first; the key ends on its own then. Shortcuts give or put back the old switches in one tap: Captain may edit, Owner authority, Temporary elevation, Sign off vendor work, Engineer.
-
The old switches are keys now
Captain may edit, Owner authority, Temporary elevation, Sign off vendor work and the engineer tag used to live only on the phone that set them. The first time the owner's phone — or a manager's — opens this version signed in and linked to the boat, it carries each switch that was on up to the cloud, once; a temporary elevation keeps its end date. Until then the stricter default applies: for example, a captain whose edit toggle was on can't change systems until that phone has opened this version. A switch the phone could not match to one person in the cloud is named under On this boat in the cloud, so you can give it under Keys by hand. After that, flipping one of those switches on a member's page also changes their keys in the cloud, when theONE can tell which person in the cloud they are.
-
What each door opens
Gangway: being aboard at all. Boat card and Boat settings: the boat's details; renaming and archiving her. Systems & engines. Run hours, service log & readings. Work orders: see, change, approve spending, sign off outside-vendor work, delete. Money: bills, costs, prices and receipts wherever they appear. Documents. Boat passwords (kept on the phone that saved them). Fuel log (the price needs the Money key). Trips & legs: see, plan, run, delete. Routes & passage planning. Tracks and the anchorage history. History from before you came aboard. Issues & observations. Incidents. Playbooks & checklists. Tasks. Stowage & inventory. Safety equipment records. Safety at sea: man overboard, float plans, depth alarms, watch handoff. Manuals. Vendors. Crew & guest cards. Guest messages. Jots & notes (each note's own sharing still decides). Foresight. Roster & keys. Invites. Audit log. Web portal.
-
What each role starts with
Owner: every key. Captain: runs the boat — money, documents, everyone's cards, work orders and approving their spending, planning and running trips, incidents, the audit log — but not changing systems, stowage or vendor cards, writing playbooks, reassigning tasks or deleting, unless given. Manager: like the captain, plus systems, stowage, vendor cards, invite codes, the web portal and giving keys below manager; not deleting, writing playbooks or changing an incident's status unless given. Crew: the boat's daily work — systems, run hours, issues, their own incidents, assigned playbooks, tasks, using stowage, safety at sea, safety-equipment records, routes and trips from the day they joined, the tracks of the trips they were on and the ones they recorded, their own fuel fills without the price, their own card. Guest: their trip, their own card, the trip's messages, and man overboard. Vendor: only the systems shared with them, and their own observations and visits there.
-
Tracks for crew
A crew member's Tracks key (Tracks: see where the boat has been) starts narrower than the whole door: Opens reads from trips they were on, and their own. They see the tracks of trips they were on and the tracks they recorded themselves, from the day they joined. The boat's whole track history is the same key in full, which the owner, management and the captain hold from the start. The cloud accepts the key in full for one crew member from the owner, or from a manager for people below manager, but this version's Keys screen has no control for it: the row already shows on, and switching it off takes the key away. Anchorage history stays with the owner, management and the captain whatever keys a crew member holds.
-
When a change was refused for a key
If something you did was refused because a key was missing, Settings → Sync Health lists it under Changes set aside and says so in plain words — with the key's name when the cloud gives it. Once you have been given the key, tap Put them back in the queue. A change the cloud asked to slow down for is not set aside: it waits and goes up by itself.
-
When a key is taken away
The phone takes off it the records behind that door: manuals, work orders, vendor cards, money amounts, history from before you joined, whatever that key opened. A message says what was removed and why: your keys changed, or your role on the boat moved down. The records stay in the cloud. If the key comes back, they come back with the next sync. A key narrowed rather than taken away keeps what it still opens, such as your own records, your trip or the playbooks assigned to you. Each value is checked on the record itself, so a key held for your own records never changes someone else's.
-
Off the network
The phone checks your keys every time you open the app, and whenever the cloud says they have changed. If it has not reached the cloud for more than a day, it makes only the changes your role's own keys allow. A key given while you were away waits until the phone hears from the cloud. A change refused for this reason says so; connect and try again.
Related
- Owner / Manager / Captain / Crew / Vendor / Guest — what can each do?Which actions are gated by role.
- The Member Users screen — invites, roles, expiryMember Users lists every active and pending membership for the active vessel, grouped by role. Pending invites show their 6-digit code so the inviter can read it out.
- Sync Health — what got dropped, and what got stuckFind entries the cloud sent that this device could not read, and changes that could not be sent and were set aside, and do something about both.
- When your access to a boat ends — and asking for more timeAccess given for set dates stops at the end date, and someone senior can take you off a boat. Either way the boat's records come off your phone; if your dates ran out, you can ask for more time.