Security & access

Review who can access a team, page, custom app, or integration and reduce access that is no longer needed.
6 min read · Reviewed

Review access at the level where it was granted: the team, an individual page, a custom app, or an API or MCP key. Checking only one level can miss access that was granted somewhere else.

Understand the access layers

Access layerWhat it controlsWhere to review it
Team membership and roleWhether a person belongs to the team and what they can do across it.SettingsPeople
Page accessWho can open or edit one page and whether the whole team can open it.The page's Share panel
Custom-app accessWho can use, edit, or manage one custom app.The app's Share panel and People tab
Programmatic accessWhich scripts, integrations, or MCP clients can access team data.SettingsAPI, MCP, and Connections

Use individual accounts for people and separate keys for separate tools. This makes access easier to review and revoke without disrupting someone else.

Review who can access the team

  1. Open the team you want to audit.
  2. Open SettingsPeople.
  3. Select Members and review each person's Role.
  4. Select Invites and review invitations that have not become active memberships.
  5. Compare Paid seats and Current members so you understand the seat impact before adding anyone.
  6. Change a person's role when they need less or more team-level access.

Choose the least role that supports the person's work. Owner and Admin can manage members and team settings; Member cannot edit team settings; Viewer cannot make changes.

Review who can access a page

  1. Open the page.
  2. Select Share in the page header.
  3. Under People with access, review the owner and anyone invited individually.
  4. Check the access level beside each person, such as Can view or Can edit.
  5. Under General access, check whether the page is limited to invited people or available to Everyone at [team name].
  6. Select Done after you finish the review.

When General access says Everyone at [team name], anyone in the current team can open the page. This is team-wide access; it does not publish the page as an anonymous website.

Give someone access to a page

  1. Open the page and select Share.
  2. Select Search people or emails....
  3. Enter the person's name or email address and select the correct person.
  4. Choose Can view when they only need to read the page, or Can edit when they need to change it.
  5. Confirm that the person appears under People with access.
  6. Select Copy link if you want to send them the page URL.
  7. Select Done.

To change or remove someone's page access, return to People with access, open the control beside their name, and choose the new access level or removal option. Confirm the result before closing the panel.

Make a page available to the team

  1. Open the page and select Share.
  2. Under General access, open the current audience setting.
  3. Select Everyone at [team name].
  4. Confirm that the panel says Anyone on the team can open it.
  5. Select Done.

Adding specific people to a team-wide page can move it from Public to Shared. Review the message in the Share panel before changing the audience.

Review custom-app access

Custom apps have their own access list, including when an app appears inside a page.

  1. Select Apps in the sidebar.
  2. Open the custom app.
  3. Select the app's Share control.
  4. Open the People tab.
  5. Review the owner and everyone who has app access.
  6. Check whether each person is a Viewer, Editor, or Owner.

Use Viewer for someone who only needs to use the shared version of the app. Use Editor only when they need to change the app. The Owner controls the app and its sharing settings, and only the owner can grant editor access.

If you can open an app but cannot see its sharing control, ask the app owner to review your access.

Change custom-app access

  1. Open Apps and select the app.
  2. Select Share and open People.
  3. Search for a teammate by name or email address.
  4. Select the person and choose the access they need.
  5. Confirm that the person appears in the app's access list.
  6. Return to People later to change their role or revoke their access.

Publishing an app to the team does not publish it as an anonymous website. App publication, page visibility, and website publishing are separate settings.

Review API, MCP, and connection access

  1. Open SettingsAPI.
  2. Review every key's label and usage information. Each label should identify the tool, owner, or purpose.
  3. Revoke keys for retired tools, departed owners, or secrets that may have been exposed.
  4. Open SettingsMCP and review the servers and keys used by MCP clients.
  5. Open SettingsConnections and review services that still have access to the team.
  6. After removing access, verify that the retired integration can no longer connect.

Create separate keys for separate tools or environments, and choose read-only access unless the integration has a reviewed need to change Bidlo data.

Troubleshoot unexpected access

If someone cannot open or edit an item, check the layers in this order:

  1. Confirm that they are signed in with the intended work account.
  2. Confirm that they opened the correct Bidlo team.
  3. In SettingsPeople, confirm that they are a member rather than a pending invite and that their role permits the action.
  4. Open the page's Share panel and review People with access and General access.
  5. If the page contains a custom app, review the app's separate People tab.
  6. Ask the person to reopen the item and confirm what they can now see or change.

FAQs

Why can someone open a page but not the app embedded in it?

Page access and custom-app access are separate. Review the app’s sharing settings and give the person the appropriate app role.

What should I revoke when a tool should no longer access Bidlo?

Revoke the specific API or MCP key used by that tool. Separate keys for separate integrations make this possible without interrupting unrelated access.