Every request to Solid Growth acts as one person. What that person may read or change is decided in the database by row level security, not in the application code, so a client cannot ask for more than the person has.
Sessions
The app signs a person in and keeps a session in a cookie. Pages, the assistant and the MCP server read that session. The sign-in screen is being rebuilt, so its address (/auth/sign-in) shows a short notice for now.
Roles
A person has one role in each workspace they belong to, from weakest to strongest:
| Role | What it can do |
|---|---|
guest | Sees only what is shared with them. |
viewer | Reads everything in the workspace and changes nothing. |
member | Reads and changes the work. |
admin | Does what a member does, and manages people and settings. |
owner | Full control, including the workspace itself. |
An owner or admin who signed in with one factor must pass a second step before any write; until then every write is refused, whatever the role.
Only your workspaces
A token and a session reach the workspaces of the person they belong to, in that person's role. Someone else's workspace and one that does not exist answer the same way, so an address never reveals which workspaces exist.