Skip to content

Custody and access in shared parcel infrastructure

Shared infrastructure means several organizations touch the same hardware. Custody has to be provable at every handover.

Security6 min read

A carrier-agnostic station is used by people who do not work for the same company: couriers from several operators, retail staff, maintenance technicians, and the recipients themselves. That is what makes the economics work, and it is also what makes access design the centre of the security model.

Every open is attributable

The base rule is that no compartment opens anonymously. Each open is tied to a credential, a role and a reason: a courier depositing against a specific parcel, a recipient collecting against a specific code, a technician acting under a maintenance task. The record of who opened which door and when is written at the moment it happens, not reconstructed afterwards.

  • Role-scoped access, so a courier credential cannot open an occupied compartment belonging to someone else.
  • Single-use collection credentials that expire with the parcel’s window.
  • Maintenance access bound to an open task and logged separately.
  • A door-level event history that survives the parcel it relates to.

Custody is a chain, not a status

Treating delivery as a status flag hides the moments that matter. Treating it as a chain means each transfer has two sides and a timestamp: sender to courier, courier to compartment, compartment to recipient. When a parcel is disputed, the question is not what the status said but which link in the chain has no matching event.

If custody cannot be reconstructed from the log, the network is asking its partners to take it on trust.

Personal data stays minimal

Operating a station needs far less personal data than most systems collect. A compartment needs to know that a credential is valid, not who a person is; an operator needs contact details for the duration of the delivery, not indefinitely. Keeping the data set small and the retention short is both a privacy position and a practical one: less data held is less data to protect.

Keep reading

Related posts.

Security5 min read

Codes, scans and credentials

Choosing an access method per user type: one-time codes for recipients, scanned credentials for couriers, task-bound access for technicians.

Security4 min read

Keeping the data set small

What a station needs to know, for how long, and why collecting less is both a privacy position and an operational one.

Last mile5 min read

Why one stop beats ten door attempts

Catchment density, not station count, is what makes a pickup network pay. How a single location earns the footprint it occupies.

See how StoreX runs in practice.