Access & Permissions
Two gates: which apps somebody can open, and what they see inside one.
App roles
| Role | Can | Cannot |
|---|---|---|
| Viewer | Open the app, read what policies allow | Edit rows, submit through app actions, change anything |
| Member | Everything a viewer can, plus create and edit rows and use the Forms | Change the app's tables, pages or Flows |
| Builder | Everything, including the app's definition | Reach an app they have no grant on |
Grants go to a person or to a team. Workspace admins are implicitly builders on every app and see every app — which is the one bypass, and it is deliberate.
Policies inside an app
The app grant is the outer gate, so the safe default inside is full access. A narrower policy is something you choose.
- A row policy is an expression over the viewer — "owner is me" — and hides rows that do not match.
- A column policy hides or read-onlys a field for the people it names.
- Bypass is app-scoped: the people with definition authority over a table are the builders of the app that owns it, plus workspace admins. There is no workspace-wide bit that unlocks another department's data.
- Machine-owned columns refuse direct writes from anybody, because the process owns them.
Preview as somebody else
Before handing an app over, preview it as a viewer or a member. You see exactly what they will — including the empty grid a policy you forgot about would leave them with. Preview is clamped to what you are yourself authorised on.
People outside the workspace
Nobody outside your company gets a login. There are exactly three things they can do, each on a link:
- Open a published page — read-only, workspace-branded, and only if nothing on it needs a viewer.
- Submit a public Form, anonymously or with an email challenge, rate limited, with uploads.
- Action a Step assigned to their email address, from a link in the notification, attributed to them.
Important: A public page cannot be written to. There is nobody to attribute a write to, so the way a visitor gives you something is always a Form.