Access control
People only see what their role and organization allow.
- ·Multi-tenant isolation by organization: queries are scoped so one workspace cannot read another’s assets or history.
- ·Role-based access: regular users, admins, and platform superusers with different privileges.
- ·Sensitive actions (billing, invites, import/export, member creation) require a verified email address.
- ·Optional TOTP two-factor authentication with one-time recovery codes and protected secret storage.
- ·Google sign-in is optional. Existing password accounts are never silently linked — linking requires a signed-in user whose email matches Google.
