Current release security foundation

CarrierHelm Stage 1 security for company onboarding and access

The current CarrierHelm release focuses on company identity, Owner onboarding, driver-seat licensing, predefined roles, invitations, seats, and access. Its security foundation is designed around authenticated identity, active company membership, role authority, seat entitlement, and controlled support paths.

Scope of this page: These controls describe the current Stage 1 access foundation. Later operational modules such as loads, dispatch, statements, fleet operations, QuickBooks, fuel, and GPS are not available in the current release and are not presented here as active security surfaces.
Current Stage 1

Company identity and membership boundary

Access is tied to the authenticated user’s active CarrierHelm company membership rather than a company value selected only in the browser.

  • Company identity established before member activation
  • Membership status checked for company access
  • Company-aware routes for authorized roles
Current Stage 1

Predefined roles and seat entitlement

CarrierHelm separates role authority from commercial driver-seat entitlement. Staff and drivers receive predefined responsibilities instead of customer-created mixed roles.

  • Company Owner, General Manager, Dispatch, Accounting, optional Fleet/Safety, and Driver roles
  • Exact driver-seat plans of 5, 10, or 20
  • Role and seat status evaluated before protected access
Current Stage 1

Controlled invitations and account matching

Owner, staff, and driver onboarding uses intentional invitations. Google Sign-In or another login method authenticates the account, but authentication alone does not create company access.

  • Invitation ownership checked against the signed-in account
  • Single-use invitation credential handling
  • No automatic company access from the public demo form
Current Stage 1

Backend-controlled access actions

Sensitive Stage 1 actions such as company initialization, membership changes, role assignment, seat activation, invitation handling, and support sessions use backend validation rather than hidden buttons alone.

  • Authenticated actor and expected role checks
  • Company, membership, and seat context checks
  • Small, purpose-specific backend commands
Current Stage 1

Controlled support-session foundation

Platform support is designed as an explicit, company-scoped, time-limited session rather than a silent permanent company role.

  • Selected company and required support reason
  • Limited support-session lifecycle
  • Separate platform and company responsibilities
Current Stage 1

Audit visibility foundation

Authorized platform and company roles have dedicated audit-viewer paths for reviewing security-relevant activity recorded by the current application.

  • Role-restricted audit access
  • Company-aware audit review
  • Security events kept separate from ordinary UI state

Fail-closed access sequence

How a protected Stage 1 access request is evaluated

  1. Authenticate the current user and verify that the session remains valid.
  2. Resolve the user’s active company membership from server-controlled records.
  3. Confirm the requested action belongs to the permitted platform or company scope.
  4. Verify predefined role authority and applicable driver-seat entitlement.
  5. Check the expected invitation, membership, role, seat, or support-session state.
  6. Execute only the permitted change and preserve the relevant audit record.

Google Sign-In does not grant company access by itself

CarrierHelm uses Google Sign-In for basic authentication and receives name, email address, profile picture, and a Google account identifier. Operational access additionally requires a valid CarrierHelm invitation, company membership, predefined role, permissions, and applicable seat status.

CarrierHelm does not use basic Google Sign-In to access Gmail messages, Google Drive files, Google Calendar, contacts, or other Google account content. See the CarrierHelm Privacy Policy for storage, retention, sharing, revocation, and deletion details.

Review the current foundation

See how Stage 1 protects onboarding, roles, seats, and company access

A CarrierHelm walkthrough can focus on the security controls that exist in the current release and separately identify the operational modules planned for later stages.

Request a focused walkthrough