Skip to content

Role capability matrix

The single source of truth for what each role can do in a syndicate. Every role-gated capability the UI exposes appears in exactly one row; the one documented exception is casting a vote, which is gated by shares rather than role, and is called out as a note rather than a row. When the code and this matrix disagree, the code wins and this page is wrong; please report it.

Anyone. This page is aimed at admins deciding which role to give a new member, but it is useful for any member who wants to understand what their fellow members can and cannot do.

This is a reference page. In the app, the role selector in the Create invite screen and the Edit member dialog is where roles are assigned.

A tick (yes) means the role can perform the action. A dash () means it cannot. A subscript note expands on a non-obvious rule.

Capability Admin Member Viewer
Create a syndicate (becomes its first admin) yes yes yes
Edit syndicate name / branding / business details yes
Close the syndicate yes
Leave the syndicate yes¹ yes¹ yes¹

¹ Not permitted if it would leave the syndicate without an admin, or while you have unresolved payments or bookings (for example, an unsettled balance, or a recent flight not yet finalised). The server enforces this; Leave a syndicate lists exactly what counts.

Capability Admin Member Viewer
View the members list yes yes yes
Invite new members yes
Change another member’s role (to admin, member, or viewer) yes
Remove a member yes
Edit own profile, timezone, and notification preferences yes yes yes
Capability Admin Member Viewer
Add an asset yes
Edit asset metadata yes
Archive / delete an asset yes
View asset details, meter readings, airworthiness yes yes yes
Capability Admin Member Viewer
View the calendar yes yes yes
Create a booking yes² yes
Pencil in a tentative booking yes yes
Confirm own tentative booking yes yes
Cancel own booking yes yes
Approve another member’s pending booking yes
Reject another member’s pending booking yes
Subscribe to personal ICS calendar feed yes yes yes

² Admin bookings skip the pending queue even when the syndicate requires approval. See Booking statuses.

Capability Admin Member Viewer
Log usage for own booking yes yes
Edit a past usage log (own) yes yes
View asset-level usage history yes yes³ yes³

³ Everyone sees the usage history itself (hours and landings); the money figures on other members’ logs are subject to the syndicate’s usage log visibility setting.

Capability Admin Member Viewer
Report a squawk yes yes
Confirm or dismiss a reported squawk yes
Defer a grounding squawk yes
Resolve a squawk yes
Add / edit maintenance items yes
Log a maintenance task yes
Defer a maintenance limit yes
Capability Admin Member Viewer
View own balance yes yes yes
Submit an expense yes yes
Approve or reject an expense yes
Set up asset billing rates yes
Create and assign billing schemes (member rates) yes
Finalise a booking yes
Bulk-finalise zero-shortfall bookings yes
Record a payment made outside the app yes
Capability Admin Member Viewer
Open a vote yes
Cancel a vote yes
Close a vote early yes

Note: casting a ballot is not role-gated, so it has no row above. It depends on whether the member holds a share, not their role: any admin, member, or viewer who is an equity member can vote, and a member with no shares cannot, regardless of role. See Vote.

Capability Admin Member Viewer
Import bookings from Goboko or CSV yes
Export a tech log (PDF / CSV) yes
Capability Admin Member Viewer
Change booking policy (approval required, advance window, minimum duration) yes
Change privacy settings (show member names, usage log visibility, share usage photos) yes
Change billing and scheme settings yes
Change subscription tier yes
  • There is no owner role. Ownership is expressed through shares; admins operate the syndicate, and the member who created it holds no special powers.
  • Role capability is enforced both in the UI (buttons are hidden) and on the server (requests are rejected). Viewer booking attempts and viewer expense submissions, in particular, are rejected server-side even if the UI were bypassed.
  • A syndicate must always keep at least one active admin. The server refuses to demote or remove the last admin of an open syndicate.
  • A member cannot be removed while they have unresolved payments or bookings (an unsettled balance, or a flight not yet finalised). This is enforced on the server; Remove a member lists what counts.
  • “Renter” is a common name for a member rate (billing scheme label), not a role. It does not appear in this matrix. See Roles and member rates.