Teams, roles and API keys

Scoped permissions for people and machines — with the dangerous capabilities split out.

What you get

  • Invite teammates by email with a role; every project starts with a full Administrator role
  • A precise permission vocabulary per module — content, schemas, media, forms, email, endpoints
  • Roles can be restricted to specific schemas
  • API keys carry exact permission lists, stored hashed, revocable instantly
  • Integration credentials and the database connection stay owner-only

Splits that reflect real risk

Sending email is separate from reading email logs, because your From address is a trusted identity. Invoking endpoints is separate from managing them, so a key can call your APIs without being able to read or rewrite their logic. Permissions map to what things can go wrong, not just to nouns.

Try it with your own data

A workspace takes about a minute.

Create your workspace