Access control that can’t be bypassed from the browser

Organization roles, custom roles, and per-space/category/room overrides - all checked on the server, every time, not just hidden in the interface.

Two axes, not one

Platform roles (for us, running the service) are entirely separate from your organization’s own roles - Owner, Admin, Manager, Member, Guest - plus any custom roles you create, plus per-space, per-category, and per-room overrides on top.

  • A denied permission is refused by the server, not just hidden in the UI
  • Overrides inherit room ← category ← space, and a deny always wins
  • The Owner always keeps every permission, so an organization can never lock itself out
ViewSendManageAdminManagerMemberGuest

Changes take effect immediately

The moment a role loses access to a room, it disappears from their sidebar - and the server refuses the request even if their browser tab hasn’t caught up yet. Access is never enforced by the frontend alone.

Bring the whole conversation together.

Set up a workspace in a couple of minutes. Free for up to 5 members, no credit card required.