Authentication

Every request to Solid Growth acts as one person.

Every request to Solid Growth acts as one person. What that person may read or change is decided in the database by row level security, not in the application code, so a client cannot ask for more than the person has.

Sessions

The app signs a person in and keeps a session in a cookie. Pages, the assistant and the MCP server read that session. The sign-in screen is being rebuilt, so its address (/auth/sign-in) shows a short notice for now.

Roles

A person has one role in each workspace they belong to, from weakest to strongest:

RoleWhat it can do
guestSees only what is shared with them.
viewerReads everything in the workspace and changes nothing.
memberReads and changes the work.
adminDoes what a member does, and manages people and settings.
ownerFull control, including the workspace itself.

An owner or admin who signed in with one factor must pass a second step before any write; until then every write is refused, whatever the role.

Only your workspaces

A token and a session reach the workspaces of the person they belong to, in that person's role. Someone else's workspace and one that does not exist answer the same way, so an address never reveals which workspaces exist.