Gavel uses “user” in a narrow sense: an owner, admin, or chair signs in to the organization console. Members, tellers, kiosk voters, and public viewers use limited links designed for a specific meeting job. Keeping those groups separate protects the organization record and makes onboarding easier.
Owner: accountable for the organization
Owners have the broadest organization access. They manage billing, exports, account deletion, bodies, users, rosters, and meetings. Only an owner can grant owner access, and Gavel protects the last active owner so the organization cannot accidentally lose its administrator of record.
Assign this role to the clerk, executive director, or another person who is authorized to make contractual and records-custody decisions. Keep at least two active owners when staff continuity matters, but do not make every meeting operator an owner.
Admin: manages people and structure
Admins manage bodies, user invitations, chair assignments, rosters, and organization settings. They can invite admins and chairs, but they cannot create or modify owners. This is the right role for a deputy clerk or program administrator who prepares the organization without controlling billing or deletion.
Chair: runs meetings
Chairs create agendas, manage the roster, open and close meetings, process motions, open votes, record attendance, and produce minutes. A chair can be scoped to selected bodies, which is useful when one organization hosts a council, planning board, and several committees.
Use chair access for the presiding officer, clerk at the dais, or meeting operator. Body scoping keeps a committee operator focused on that committee without exposing unrelated meeting workspaces.
Member: a roster identity, not a console account
Members do not need passwords or organization-console access. Each active roster member receives a personal voting link or QR code. That link identifies the member for attendance and electronic votes while keeping administrative controls out of reach.
Voting, non-voting, and tie-break-only status belong to the roster entry. Deactivating a member revokes their voting link without erasing the historical meeting record.
Teller: temporary authority for one meeting
A teller uses a labeled, meeting-scoped access link to enter choices for present members during an open electronic vote. Every teller-entered cast is attributed and appears live in the chair’s oversight grid. The access link is revoked when the meeting ends.
Create teller access for a named clerk or election assistant only when the meeting’s procedures call for assisted vote entry. It is not a substitute for an admin or chair account.
Kiosk: shared hardware for member self-service
A kiosk is a meeting-scoped shared device, not a person. A member selects their name, confirms a PIN when one is configured, and casts their own vote. Kiosk links should be staged on supervised chamber hardware and revoked after the meeting.
Public viewer: read-only by design
Public viewers need no account. Published agendas, live meeting state, results, and adopted records are available through public links. Draft work and administrative controls remain behind organization authentication.
Platform admin: support, not an organization role
Platform-admin access is reserved for Gavel operations. It is assigned outside an organization’s invitation flow and is used for account-level support, manual billing, and audited platform operations. Organizations should never grant a regular staff member this role to solve a local permissions problem.
A practical starting assignment
- Give two records-custody or executive staff members owner access.
- Use admin for staff who maintain users, bodies, and rosters.
- Use chair for people who prepare and operate meetings.
- Keep voting members on personal member links instead of console accounts.
- Create teller and kiosk links only for meetings that need them.