Appearance
Platform
Status: the traveler storage flow is in development. The courier app, organization administration split, and staff web cutover are proposed and not released.
Two apps plus one website serve distinct roles. Each surface sees only what its role needs. Hiding a screen is never treated as permission — access is checked on the server side.
Related: Storage · Delivery · Roadmap · Release decisions
The three surfaces
| Surface | Who uses it | What it does |
|---|---|---|
| Traveler app | Travelers | Search and book storage, pay, show claim code; separately quote and pay for delivery, optionally link a storage booking, and follow custody milestones. |
| Courier app (proposed) | Assigned couriers | Sign in, see only assigned jobs, accept work, navigate to the task, record pickup and delivery proof, and report exceptions with safe retry on poor connectivity. |
| Website (proposed org split) | Oversight, organization operations, staff | Superadmin manages organizations and platform oversight; organization admins manage only their own people, locations, bookings, deliveries, dispatch, and reports; staff perform storage handoffs only. |
Roles
| Role | Responsibilities |
|---|---|
| Traveler | Books and pays for storage or delivery, presents claim or hands over bags, follows status. |
| Courier (proposed) | Completes assigned delivery jobs with verified proof; reports inability to collect or deliver. |
| Store / location staff | Scan claim codes and record photo, tag, check-in, and check-out at authorized locations. |
| Organization admin (proposed) | Manages its organization's venues, staff, couriers, bookings, deliveries, manual dispatch, and reports. |
| Superadmin (proposed) | Manages organizations, membership assignment, policy, and platform oversight. |
Access boundaries
- One identity per person; authority comes from organization membership plus a separately controlled oversight grant, not from a self-declared role label.
- A person may belong to more than one organization; every organization-scoped request states its context and is checked against an active membership.
- A courier belongs to one organization in the first release. Shared cross-organization courier pools are a later, separate model.
- Storage bookings, delivery orders, and courier jobs have distinct lifecycles. A storage pick-up time is not courier collection proof, and a notification is not custody proof.
- Customer contact details, precise addresses, and proof photos are visible only to the assigned courier while needed for the active job, the responsible organization operators, and the customer.
Staff cutover (proposed)
The current in-app staff scan route stays in place until a mobile-friendly staff web surface reaches parity on a phone — claim lookup, photo, tag, check-in and check-out, and offline recovery. Only then is the old route removed. No customer or courier app contains an organization-admin surface.