Access control
Public pages, members-only areas, and admin pages gated to your team.
By default, pages are public: anyone with the URL can see them. When you need to put a page behind a sign-in, your agent adds a gate. There are three shapes worth knowing, because they decide who gets in and what you learn about them.
#Public
The default. Fast, cacheable, open to the world. Right for marketing pages, blogs, docs, storefronts, anything meant to be found.
#Members-only
A page gated so that anyone signed in can view it, but anonymous visitors can't. Good for a members area, a gated download, a community space.
With a members-only page, you can give each visitor their own content (a personal dashboard, saved items, a profile) keyed to a stable, anonymous identifier for that person. You don't learn their email or name; if you want those, your page asks for them and stores what the visitor chooses to give. That's privacy by default: a stranger reading a gated page isn't someone you automatically get the contact details of. (The identifier is derived per-site, so the same person shows up as a different id on two different Tessryx sites and the two can't be cross-referenced.)
A visitor signs in through a Tessryx-hosted sign-in step (there's no password for you to manage) and their session lasts about 30 minutes; after a longer gap they sign in again. Design gated pages to tolerate the occasional re-sign-in.
#Team-only (admin pages)
A page gated to your team, by role. This is how you build an admin area (edit content from the site itself, run internal tools) without exposing it to the public or to other Tessryx users. Because these people are your own team members, the page can see who they are (name, email, role) and adjust what each one can do.
Access is checked live on every visit, so removing someone's role takes effect immediately.
#Team roles
Your workspace members hold one of these roles, set in Members (see Team):
Roles are cumulative: each can do everything the one below it can, plus more:
| Role | Can |
|---|---|
| Owner | Everything an Admin can, plus manage team members, billing, and deleting the workspace |
| Admin | Everything a Maintainer can, plus set secrets and custom domains |
| Maintainer | Build and publish everything: schemas, pages, workflows, integrations, schedules, apps |
| Editor | Edit and publish content, upload media, and run workflows |
| Viewer | Read everything in the workspace; change nothing |
Roles do double duty: they govern what someone can do inside the web app, and they're what a team-only page checks to decide who gets in.
#A note on caching
A gated page is never shared-cached. It can't be, or one person's private view might be served to someone else. That's automatic and correct, but it means gated pages don't get the same edge-cache speed-up public pages do. Keep the truly public parts public so they stay fast and cheap; see Credits and caching.