> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.chrt.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.chrt.com/_mcp/server.

# Roles and Permissions

> The four organization roles chrt uses — owner, admin, operator, and member — and the permission matrix for orders, billing, connections, rate sheets, and drivers. Plus how driver users fit in.

Every user on chrt belongs to one or more **organizations**, and inside each
organization they hold one **role**. The role determines which UI surfaces
they can see and which actions they can take. chrt also has a separate notion
of a **driver** — a member of a provider org who has a driver profile and uses
the chrt mobile app.

## The four organization roles

The `OrgRoleEnum` defines four roles, in descending authority:

| Role         | Use it for                                                                                                                                                           |
| ------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Owner**    | The org's founder or principal. Owns billing setup and Stripe Connect. Cannot be removed except by another owner.                                                    |
| **Admin**    | Trusted operators with full management rights — invite users, manage rate sheets, configure billing, manage notification groups.                                     |
| **Operator** | Day-to-day dispatch and operations. Can run orders end-to-end (cancel, edit, assign drivers, add line items) but cannot change billing setup or notification groups. |
| **Member**   | Lowest tier. Can view what they have access to and use the chrt mobile app if they're set up as a driver.                                                            |

Hierarchy: `owner > admin > operator > member`. Most permission checks are
"admin-or-higher" or "operator-or-higher", so granting Admin grants everything
Operator can do, and so on.

## Permission matrix

Permissions are mode-aware: many actions only exist for **provider** orgs
(forwarders + couriers) or **shipper** orgs. See [Connections](/docs/concepts/connections)
for the mode distinction.

| Capability                                               | Owner | Admin | Operator | Member           |
| -------------------------------------------------------- | ----- | ----- | -------- | ---------------- |
| View org data, orders, statements                        | Yes   | Yes   | Yes      | Yes              |
| Edit own profile                                         | Yes   | Yes   | Yes      | Yes              |
| Invite or remove org members                             | Yes   | Yes   | —        | —                |
| Manage Stripe Connect / billing setup                    | Yes   | Yes   | —        | —                |
| Manage notification groups (org-wide)                    | Yes   | Yes   | —        | —                |
| Create, edit, archive rate sheets (owned vectors)        | Yes   | Yes   | —        | —                |
| Manage drivers (provider only)                           | Yes   | Yes   | Yes      | own profile only |
| Assign a driver to a task group (provider only)          | Yes   | Yes   | Yes      | —                |
| Cancel or edit an order (provider only)                  | Yes   | Yes   | Yes      | —                |
| Add / remove line items, adjust invoices (provider only) | Yes   | Yes   | Yes      | —                |
| Manage address book (shipper only)                       | Yes   | Yes   | —        | —                |
| View own connections                                     | Yes   | Yes   | Yes      | Yes              |
| Manage connections                                       | Yes   | Yes   | Yes      | Yes              |

A few rows worth flagging:

* **Cancel / edit order** is provider-only. Shippers cannot cancel an order
  once it is staged — they must ask the provider running it.
* **Driver payouts** (provider-pay-driver rate sheets, driver expense
  statements) are provider-only and require admin-or-higher to manage.
* **Notification groups** are gated tighter than other admin actions — only
  owners and admins, not operators.

## Drivers

A **driver** is not a fourth org role. It's an additional profile attached to
a **member** (or any role, in practice) of a **provider** org. A driver
profile gives the user access to the chrt mobile app, lets them be assigned
to task groups, and ties their location updates back to those task groups.

You create a driver by:

1. Inviting the person to your provider org as a Member (see
   [Add an org member](/help/getting-started/add-org-member)).
2. Creating a driver profile for them under
   [chrt.com/drivers](https://chrt.com/drivers).

A user can be a driver in one provider org and a regular Admin or Member in
another — drivers are scoped per-org.

> **Note**
>
> Shipper orgs do not have drivers. Drivers are a provider-org concept only.

## Modes vs roles

Don't confuse a **role** (owner / admin / operator / member) with a **mode**
(shipper / provider). The org's type is fixed at setup time; the role is
per-user, per-org. A provider org with one owner and three operators is the
common shape for a small courier company.

## Related guides

* [Connections](/docs/concepts/connections) — the shipper / provider
  distinction and how orgs link up.
* [Billing primitives](/docs/concepts/billing-primitives) — which roles can
  manage rate sheets and statements.
* [Add an organization member](/help/getting-started/add-org-member) — how to
  invite users and pick a role.
* [Manage drivers (couriers)](/couriers/drivers) — driver profiles, the
  driver app, and assignment.