Security and access

Give each person only the access they need.

Supahost checks the workspace, property scope, role, and approval before it reads or changes protected records.

Make sensitive actions deliberate.

Access follows the person, workspace, property, and action instead of relying on a hidden screen or shared link.

Staff access
Check role and workspace scope on the server before protected data is returned.
Owner access
Limit each session to published statements for that owner and workspace.
Leah's access
Show her read trail, then require an authorized person to approve each write.
Drafts and internal workspace data stay private
Least visible by default
Sensitive links redeem only after an intentional action
Short-lived invitations
Authorized writes keep actor and result together
Approval receipts

AI authority

A helpful agent is not an unbounded agent.

Leah can inspect permitted records and prepare an action. An authorized person decides whether to apply it.

Visible tool trail
The thread shows which sources Leah inspected before reaching a conclusion.
No silent writes
Approve and deny controls sit beside the exact proposed change.

Owner isolation

Publication creates a narrow, read-only window.

An owner can read their published statements. The session cannot enter the staff app, browse drafts, or cross owner relationships.

Intentional redemption
Invitation links render a confirmation first and redeem through an explicit POST.
Hosted custom domains
Verified aliases resolve to the portal while Supahost remains the operator.

Evaluate the boundaries with us.

Sign up and we will walk through your workspace roles, owner relationships, and approval requirements before onboarding.