Security and data
Tenant isolation
A workspace never sees another workspace's data. That is the product, not a quality bar.
Every site, backup, update round, client, package, monitor, API key and member belongs to exactly one workspace, and everything the dashboard and the API show is scoped to the workspace of the caller. That is not something a screen opts into: it is how every screen and every endpoint is built, and a change to the platform is not accepted until it has been shown to hold.
What this means in practice
- A member of workspace A cannot open, list, search or act on anything in workspace B, whatever address they type.
- An API key of workspace A returns only workspace A's sites.
- A site's own calls to the platform are accepted only as the site registered in the workspace whose token the site presented, and as nothing else.
- Selecting many sites in a list gives nobody more than they have on one site. A member allowed to view sites but not to act on them cannot act on all of them at once through a checkbox.
What a client member sees
A member with the client role sees only the sites of the client accounts they are attached to, read-only: status, update rounds, backups, plugins, themes, core, health, reports, notes and monitoring. They cannot start anything, restore anything, or log in to a site through the dashboard.