Control & Access
Access that binds even the owner
A platform ceiling above the owner short-circuit, per-page grants enforced in row-level security, and portals that keep outsiders outside.
Entitlement, enforced in the schema
Two authoritative tiers
A platform ceiling per workspace and a per-member grant beneath it, resolved by the same functions the database uses.
Blocked means blocked
Page access backs row-level security across the schema, so a blocked module is blocked for API tokens and exports, not merely hidden.
Read-only as a tier
Look-but-do-not-touch seats for owners, auditors and handovers. Exports still work; approvals do not.
Effective access, previewed
The panel resolves what a member can actually do, page by page, mirroring the database’s own answer.
Provision in one sitting
Workspace, modules, quotas, up to one hundred members with roles and overrides, and generated credentials in a single wizard.
Tokens shown once
API tokens are scoped, hashed at rest and revocable fleet-wide. Invitation secrets have no read path at all.
The matrix that binds every seat
Groups, pages, ceilings, and the effective answer per member, exactly as the operator resolves it.
132
catalog pages governed
567
row-level security policies
6
per-action grants
