stepbase

Public Pages & Branding

What a stranger can open, and the rules that decide it.

Three doors, and no accounts

SurfaceWhat a stranger can do
A published pageBrowse the catalog of request types, read the collections the page exposes. Workspace-branded.
A public FormSubmit. Anonymous or email-challenged, rate limited, with uploads, QR codes and embeds.
An external task linkAction a Step assigned to their email address, attributed to them.

What a page may do once it is public

A public link has no viewer, and that single fact decides everything. Three consequences, each enforced rather than documented and hoped for:

  • There is nobody to evaluate a policy against, so a table carrying a row policy cannot be served publicly at all. The link is refused, naming the table.
  • There is nobody to attribute a write to, so a public page is read-only. Collect with a Form, which knows who submitted, keeps the record, and has its own rate limit.
  • There is no row, so record pages, related lists, timelines, steppers and the process panel are all refused by name.
Note: The process panel is refused on stronger grounds than the rest: it names who owes the next approval and who signed off on the last one, which is not a visitor's to see even when a row could be resolved.

Branding

Published pages and Forms carry your workspace's logo and colours. Per-app branding is available on the enterprise plan. There is no custom domain — links are stepbase URLs.

Next: Templates