Skip to main content
This page is the single source of truth for every permission-gated action in Quiverstone. If you hit an error like “You don’t have permission to do that,” check here first — the combination of your subscription tier, team type, and team role determines what you can do.
Permissions are evaluated at request time. Upgrading a subscription or changing someone’s team role takes effect immediately; no sign-out is required.

Terminology refresher

  • Tier — the subscription plan: Free, Consultant, Pro, or Enterprise. See Subscriptions & Tiers.
  • Team typeACCESS (consumers) or SETTINGS (admins). See Teams.
  • Team roleOWNER, ADMIN, or MEMBER, assigned per team per user.
Every user is either not on any team (Free), on the single Consultant team, or on one or more Pro/Enterprise teams.

Workspace & subscription

Teams

A team must always have at least one OWNER. The system will refuse to demote or remove the last remaining OWNER of a team.

Organizations, Accounts, and Customers

These three resource types share the same permission model.
On Pro and Enterprise, ACCESS team members see nothing until a SETTINGS member adds them (directly or via their team) to a Group that references the resource.

Groups

Groups only exist on Pro and Enterprise. Consultant tier shares everything automatically and does not expose the Groups UI. See Groups for the full model.

Roles (IAM role records)

A Role in Quiverstone is a saved AWS IAM role configuration (ARN, External ID, session name, optional chain). Roles are attached to Groups — you cannot grant a Role directly to a user.

”Why can’t I…?” quick index

Use this table to jump straight to the likely cause of a permission error.