Access control that can’t be bypassed from the browser
Organization roles, custom roles, and per-space/category/room overrides - all checked on the server, every time, not just hidden in the interface.
Two axes, not one
Platform roles (for us, running the service) are entirely separate from your organization’s own roles - Owner, Admin, Manager, Member, Guest - plus any custom roles you create, plus per-space, per-category, and per-room overrides on top.
- A denied permission is refused by the server, not just hidden in the UI
- Overrides inherit room ← category ← space, and a deny always wins
- The Owner always keeps every permission, so an organization can never lock itself out
Changes take effect immediately
The moment a role loses access to a room, it disappears from their sidebar - and the server refuses the request even if their browser tab hasn’t caught up yet. Access is never enforced by the frontend alone.
Bring the whole conversation together.
Set up a workspace in a couple of minutes. Free for up to 5 members, no credit card required.
