Permissions — who can see what, by role
Who sees what, by role — and the two rules that decide it.
theONE has memberships per vessel with role-based access. Two rules decide everything:
1. Some records belong to ownership, not to operations. The expense report, what fuel costs (the fuel log's prices and receipts; crew log the fills themselves), the document vault, anchorage history, and the crew and guest cards — allergies, dietary and medical notes included — are for the owner, management and the captain. One exception: each person sees their own card, and can edit it (Settings → Account → My card; a guest, the My guest card row on their Your trip screen, with their own account signed in). Other crew do not see it. A captain running the boat needs the insurance papers, the registration and the anchorage record — so the captain is inside this line, not outside it.
2. Crew see their own time aboard. A crew member joining in June reads the deck logbook from June forward, not from March. Owner, management and captain see the whole history, because they carry responsibility for what happened before them.
Open work is never hidden. An observation raised in March that is still open is today's job. It shows for whoever is sent to fix it, regardless of when it was raised or when they came aboard. The line is closed record versus live work — not old versus new. Hiding a live safety item from the person standing in front of it would be dangerous, not private.
The roles broadly:
- Owner — everything.
- Management — everything operational plus the vessel records above.
- Captain — operations, plus the vessel records: vault, anchorage history, expenses, the fuel log, and every crew and guest card, medical notes included.
- Crew — operations from their time aboard. Log entries, observations, trips, maintenance, playbooks. Tracks: the tracks of trips they were on and the tracks they recorded themselves, not the boat's whole track history. The fuel log's fills — gallons, tanks, engine hours — which they add to, changing or deleting only their own; never what fuel costs, and no receipts. Their own card, which they can edit. Not the vault, not expenses, not anchorage history, and not anyone else's card.
- Vendor — the systems an owner, captain or manager shares with them (none until someone does), each with its service history, run hours, work orders and observations — never a cost or a bill — plus the observations and work sessions they write themselves. Sharing ends when their access ends.
- Guest — aboard for one trip, and very little more. On their own phone a guest's theONE is one screen, Your trip: the trip, Message the crew and My guest card. A guest sees no operational record: not the logbook, not observations, not maintenance, not costs, not documents, not crew details, and not the stowage lockers. They are on the boat's list of people, not in its files.
The menu narrows too. A vendor never gets the captain's menu, not even with rows locked: on the More tab the hamburger carries one group, Help (Help Center and Take the tour), and on the Mission Control and Observations tabs it has no Help row at all. A guest has no hamburger; the Your trip screen is all there is.
If a screen refuses you, it says so plainly rather than showing you an empty version of itself.
Steps
-
The ownership line
Expense Report, the Fuel Log's prices and receipts, Documents, Anchorage History, and the crew and guest cards with their allergies, dietary and medical notes: owner, management and captain. Crew and vendors are not offered Expense Report or Documents in the menu, rather than shown them and refused; crew are offered Fuel Log, without prices or receipts, and vendors are not; the Crew Book and the Ship's Directory show them their own card and nobody else's. If the boat's cloud stops sending you these records — your part on the boat changed, say from manager to crew — they come off your phone the next time it reaches the cloud: the expense report, the fuel log, the documents and their scans, and every card but your own. They stay with the boat, in the cloud and on the officers' phones, and come back if the cloud sends them to you again.
-
The time line — narrower than it sounds
Crew read records dated from the day they joined forward. The window covers trips and their legs, tracks, incidents, man-overboard pins, float plans, watch hand-offs and depth-margin alarms: those from before a crew member's start date are held back from their phone, by the cloud as well as the app. It covers the deck logbook too, and the precedent a Foresight card cites (a past record closed before they came aboard is not cited to them). Closed observations and service history are not windowed by join date.
One exception: crew tagged as engineers (the Engineer shortcut under Keys) read the whole history, because an engineer diagnosing a fault needs what happened before they came aboard.
-
What is never scoped
Live work. Open observations, current maintenance, active playbooks and safety items show for whoever needs them, whenever they were created.
-
Changing someone's role
On the member's page the role is a label, not a control: A MEMBER'S ROLE ITSELF CANNOT BE CHANGED. To put someone on a different role, revoke and re-invite them at the role you want.
One thing can change: the owner can make a captain the manager as well — Menu (☰) → Settings → Member Users → On this boat in the cloud → the captain's row → Also the manager. The owner can do the same on the web portal — the web version of the boat, open to the owner and the manager: there too a captain can be made manager as well, or stop being one. The captain keeps the Captain role and acts with a manager's authority; only the owner can switch it, and it ends if the captain leaves the boat. See Member Users.
What you can also do from the member's page: set their access state (Active, Familiarization or Blocked), set their specialties, resend or revoke an invitation. There is no 'More → Crew' path — the roster is Member Users, inside Settings.
Related
- Owner / Manager / Captain / Crew / Vendor / Guest — what can each do?Which actions are gated by role.
- Invite crew or a co-ownerAdd people who help run the boat.
- Pre-expiry banners and extension requestsWith notifications allowed, theONE notifies you 12 hours, 6 hours and 1 hour before your access toggle expires, and tapping one opens a sheet to acknowledge or request an extension. With notifications off, a banner counts the last 24 hours down instead.
- Bring a guest aboardHow to add someone who is aboard but is not crew.