A carrier-agnostic station is used by people who do not work for the same company: couriers from several operators, retail staff, maintenance technicians, and the recipients themselves. That is what makes the economics work, and it is also what makes access design the centre of the security model.
Every open is attributable
The base rule is that no compartment opens anonymously. Each open is tied to a credential, a role and a reason: a courier depositing against a specific parcel, a recipient collecting against a specific code, a technician acting under a maintenance task. The record of who opened which door and when is written at the moment it happens, not reconstructed afterwards.
- Role-scoped access, so a courier credential cannot open an occupied compartment belonging to someone else.
- Single-use collection credentials that expire with the parcel’s window.
- Maintenance access bound to an open task and logged separately.
- A door-level event history that survives the parcel it relates to.
Custody is a chain, not a status
Treating delivery as a status flag hides the moments that matter. Treating it as a chain means each transfer has two sides and a timestamp: sender to courier, courier to compartment, compartment to recipient. When a parcel is disputed, the question is not what the status said but which link in the chain has no matching event.
If custody cannot be reconstructed from the log, the network is asking its partners to take it on trust.
Personal data stays minimal
Operating a station needs far less personal data than most systems collect. A compartment needs to know that a credential is valid, not who a person is; an operator needs contact details for the duration of the delivery, not indefinitely. Keeping the data set small and the retention short is both a privacy position and a practical one: less data held is less data to protect.


