Skip to main content
This page is the single source of truth for every permission-gated action in Quiverstone. If you hit an error like “You don’t have permission to do that,” check here first — the combination of your subscription tier, team type, and team role determines what you can do.
Permissions are evaluated at request time. Upgrading a subscription or changing someone’s team role takes effect immediately; no sign-out is required.

Terminology refresher

  • Tier — the subscription plan: Free, Consultant, Pro, or Enterprise. See Subscriptions & Tiers.
  • Team typeACCESS (consumers) or SETTINGS (admins). See Teams.
  • Team roleOWNER, ADMIN, or MEMBER, assigned per team per user.
Every user is either not on any team (Free), on the single Consultant team, or on one or more Pro/Enterprise teams.

Workspace & subscription

ActionFreeConsultantPro / Enterprise
Manage billing and upgrade the subscriptionOwnerOwnerSETTINGS OWNER
Invite new usersOwnerSETTINGS members; team OWNER/ADMIN within their own team
Remove a user from a teamOwnerSETTINGS OWNER; team OWNER/ADMIN within their own team
Transfer subscription ownershipOwnerOwnerSETTINGS OWNER

Teams

ActionFreeConsultantPro / Enterprise
Create a team— (fixed single team)SETTINGS members
Edit team detailsOwnerTeam OWNER/ADMIN; any SETTINGS OWNER
Invite a team memberOwnerTeam OWNER/ADMIN; any SETTINGS member
Promote a member to ADMIN— (locked to MEMBER)Team OWNER
Promote a member to OWNERCurrent team OWNER
Delete a teamTeam OWNER; any SETTINGS OWNER
Choose team type (ACCESS vs SETTINGS) at creation— (locked to ACCESS)SETTINGS members
A team must always have at least one OWNER. The system will refuse to demote or remove the last remaining OWNER of a team.

Organizations, Accounts, and Customers

These three resource types share the same permission model.
ActionFreeConsultantPro / Enterprise
Create a recordOwnerOwner onlySETTINGS members only
Edit or delete a recordOwnerOwner onlyAny SETTINGS member (automatic co-ownership)
View a recordOwnerEvery team member (automatic)Record owner + any SETTINGS member + any user explicitly added via a Group
Assume an AWS role on a linked AccountOwnerEvery team memberRecord owner + any SETTINGS member + any Group member whose Group attaches that Role
On Pro and Enterprise, ACCESS team members see nothing until a SETTINGS member adds them (directly or via their team) to a Group that references the resource.

Groups

Groups only exist on Pro and Enterprise. Consultant tier shares everything automatically and does not expose the Groups UI.
ActionFreeConsultantPro / Enterprise
Create a GroupSETTINGS members
Edit a GroupGroup creator; any SETTINGS OWNER
Delete a GroupGroup creator; any SETTINGS OWNER
Be referenced in a GroupAny user or ACCESS team in the subscription
See Groups for the full model.

Roles (IAM role records)

A Role in Quiverstone is a saved AWS IAM role configuration (ARN, External ID, session name, optional chain). Roles are attached to Groups — you cannot grant a Role directly to a user.
ActionFreeConsultantPro / Enterprise
Create a Role recordOwnerOwnerSETTINGS members
Edit or delete a Role recordOwnerOwnerAny SETTINGS member
Attach a Role to a GroupSETTINGS members
Assume a Role into an AWS accountOwnerEvery team memberAny user whose Group membership attaches that Role to a linked Account

”Why can’t I…?” quick index

Use this table to jump straight to the likely cause of a permission error.
Error you’re seeingLikely causeFix
”You cannot create Organizations”You’re on Pro/Enterprise but not on a SETTINGS team.Ask a SETTINGS team OWNER to add you to one.
”You cannot create teams” on ConsultantConsultant tier is capped at one team.Upgrade to Pro.
”You cannot promote this member” on ConsultantConsultant tier locks non-owners to MEMBER.Upgrade to Pro.
”You cannot delete this Group”Groups can only be deleted by their creator or a SETTINGS OWNER.Have a SETTINGS OWNER delete it, or ask the creator.
”This Account is not visible” as an ACCESS team memberNo Group attaches that Account to you or your team.Ask a SETTINGS member to add you to a Group that includes the Account.
”Cannot demote the last OWNER”Every team must have at least one OWNER.Promote another member to OWNER first, then demote.
”You cannot invite more members”You have hit your tier’s seat cap (3 on Consultant, 10 on Pro).Upgrade or remove an existing member.