Platform & Operations

Many workspaces. One install.

A project groups pages, collections, forms, blocks, components, endpoints and tokens under a name. Scope a user to it and the whole admin follows them into it.

ProjectsRoles you defineRow-level access

A name that everything hangs off.

Artefacts carry an optional project tag, and the sidebar groups them by it. Anything untagged belongs to the default project by resolution, not by being stamped, so adopting projects on an existing site changes nothing until you want it to.

Pages, collections, forms, blocks and components
API endpoints and API tokens, bound to the project
Per-project overview, settings and sidebar section
A scaffolder that stamps new artefacts with the project

Ownership and reach are different things.

Where a user lives and what a user can reach are stored separately, on purpose.

One decides where they land and how the sidebar is arranged for them. The other is a list of projects they are allowed into, and an empty list means unrestricted rather than locked out.

Conflating the two is how you end up with an administrator who cannot see the site they administer.


Roles are data, not constants.

Define your own

Three roles are seeded on first run - Super Admin, Admin and User - and you add as many as you like. Tools bring roles of their own too, such as a job board's candidates. A role can even be confined to a few admin screens with its own home: see Users, roles and security.

One permission map

Every route guard asks a central permission registry what a resource requires, rather than testing for a role name. Grant a new role access to collections and every collection route honours it immediately.

Down to the row

Row-level access decides which entries of a collection a given user can see, by role or by ownership, evaluated on the server before anything is rendered.


Agencies, mostly.

One install, one update, many clients. Each client gets a project, their users get access to that project, and nobody sees anybody else's work in a list.

When one install per client is the right answer instead, the managed fleet runs many sites from one control plane with rolling updates and health checks.

Managed hosting →

An editor who cannot break the site.

Give writers a role that reaches pages and media and nothing else. Give a data entry role one collection. Give a client a login that sees their own project and stops there.

Because the permission map is central, a new role is a decision you make once rather than a set of checks you have to remember to add.