Teams, rights and the cabinet
Who owns what
The site knows who you are and which teams you belong to. The canvas server decides what you may do on the canvas and checks it on every edit. The team cabinet lives in the app: people, roles, invitations, groups, rights, integration keys. The site keeps the account, plans and documents.
Roles
A role in a team sets the ceiling: owner, administrator, member, viewer. There is one owner; the owner cannot be removed or demoted, only ownership can be transferred. A personal team cannot be deleted.
Invitations
An invitation goes out by e-mail and as a link, lasts a week and works only for the address it was sent to. You can forward the link yourself if the e-mail did not arrive.
Grants
Within the ceiling, rights are narrowed by grants: per project, layer or namespace, for a person or a group. Levels: read, comment, write, manage, edit types. A read ban hides nodes and their edges rather than merely forbidding edits.
Capabilities
Actions with an external effect are granted separately: SQL, HTTP, files, code execution. By default only the owner and administrators have them.
Public links
A link opens a workspace to a viewer without an account. Revoking a link ends its sessions immediately. A link grants nothing beyond the weakest member.
Archive
A team can be frozen by archiving: reading and taking your own data out still works, writing, inviting and creating do not. It is reversible. Deleting an owner's account archives their teams for the grace period.