Open beta: every plan is 100% off for the duration of testing. Found a flaw or have an idea — tell us.

Teams, rights and the cabinet

Who owns what

The site knows who you are and which teams you belong to. The canvas server decides what you may do on the canvas and checks it on every edit. The team cabinet lives in the app: people, roles, invitations, groups, rights, integration keys. The site keeps the account, plans and documents.

Roles

A role in a team sets the ceiling: owner, administrator, member, viewer. There is one owner; the owner cannot be removed or demoted, only ownership can be transferred. A personal team cannot be deleted.

Invitations

An invitation goes out by e-mail and as a link, lasts a week and works only for the address it was sent to. You can forward the link yourself if the e-mail did not arrive.

Grants

Within the ceiling, rights are narrowed by grants: per project, layer or namespace, for a person or a group. Levels: read, comment, write, manage, edit types. A read ban hides nodes and their edges rather than merely forbidding edits.

Capabilities

Actions with an external effect are granted separately: SQL, HTTP, files, code execution. By default only the owner and administrators have them.

Public links

A link opens a workspace to a viewer without an account. Revoking a link ends its sessions immediately. A link grants nothing beyond the weakest member.

Archive

A team can be frozen by archiving: reading and taking your own data out still works, writing, inviting and creating do not. It is reversible. Deleting an owner's account archives their teams for the grace period.

← f2plw languages