Security & access
Review access at the level where it was granted: the team, an individual page, a custom app, or an API or MCP key. Checking only one level can miss access that was granted somewhere else.
Understand the access layers
| Access layer | What it controls | Where to review it |
|---|---|---|
| Team membership and role | Whether a person belongs to the team and what they can do across it. | Settings → People |
| Page access | Who can open or edit one page and whether the whole team can open it. | The page's Share panel |
| Custom-app access | Who can use, edit, or manage one custom app. | The app's Share panel and People tab |
| Programmatic access | Which scripts, integrations, or MCP clients can access team data. | Settings → API, MCP, and Connections |
Use individual accounts for people and separate keys for separate tools. This makes access easier to review and revoke without disrupting someone else.
Review who can access the team
- Open the team you want to audit.
- Open
Settings→People. - Select
Membersand review each person'sRole. - Select
Invitesand review invitations that have not become active memberships. - Compare
Paid seatsandCurrent membersso you understand the seat impact before adding anyone. - Change a person's role when they need less or more team-level access.
Choose the least role that supports the person's work. Owner and Admin can manage members and team settings; Member cannot edit team settings; Viewer cannot make changes.
Review who can access a page
- Open the page.
- Select
Sharein the page header. - Under
People with access, review the owner and anyone invited individually. - Check the access level beside each person, such as
Can vieworCan edit. - Under
General access, check whether the page is limited to invited people or available toEveryone at [team name]. - Select
Doneafter you finish the review.
When General access says Everyone at [team name], anyone in the current team can open the page. This is team-wide access; it does not publish the page as an anonymous website.
Give someone access to a page
- Open the page and select
Share. - Select
Search people or emails.... - Enter the person's name or email address and select the correct person.
- Choose
Can viewwhen they only need to read the page, orCan editwhen they need to change it. - Confirm that the person appears under
People with access. - Select
Copy linkif you want to send them the page URL. - Select
Done.
To change or remove someone's page access, return to People with access, open the control beside their name, and choose the new access level or removal option. Confirm the result before closing the panel.
Make a page available to the team
- Open the page and select
Share. - Under
General access, open the current audience setting. - Select
Everyone at [team name]. - Confirm that the panel says
Anyone on the team can open it. - Select
Done.
Adding specific people to a team-wide page can move it from Public to Shared. Review the message in the Share panel before changing the audience.
Review custom-app access
Custom apps have their own access list, including when an app appears inside a page.
- Select
Appsin the sidebar. - Open the custom app.
- Select the app's
Sharecontrol. - Open the
Peopletab. - Review the owner and everyone who has app access.
- Check whether each person is a
Viewer,Editor, orOwner.
Use Viewer for someone who only needs to use the shared version of the app. Use Editor only when they need to change the app. The Owner controls the app and its sharing settings, and only the owner can grant editor access.
If you can open an app but cannot see its sharing control, ask the app owner to review your access.
Change custom-app access
- Open
Appsand select the app. - Select
Shareand openPeople. - Search for a teammate by name or email address.
- Select the person and choose the access they need.
- Confirm that the person appears in the app's access list.
- Return to
Peoplelater to change their role or revoke their access.
Publishing an app to the team does not publish it as an anonymous website. App publication, page visibility, and website publishing are separate settings.
Review API, MCP, and connection access
- Open
Settings→API. - Review every key's label and usage information. Each label should identify the tool, owner, or purpose.
- Revoke keys for retired tools, departed owners, or secrets that may have been exposed.
- Open
Settings→MCPand review the servers and keys used by MCP clients. - Open
Settings→Connectionsand review services that still have access to the team. - After removing access, verify that the retired integration can no longer connect.
Create separate keys for separate tools or environments, and choose read-only access unless the integration has a reviewed need to change Bidlo data.
Troubleshoot unexpected access
If someone cannot open or edit an item, check the layers in this order:
- Confirm that they are signed in with the intended work account.
- Confirm that they opened the correct Bidlo team.
- In
Settings→People, confirm that they are a member rather than a pending invite and that their role permits the action. - Open the page's
Sharepanel and reviewPeople with accessandGeneral access. - If the page contains a custom app, review the app's separate
Peopletab. - Ask the person to reopen the item and confirm what they can now see or change.
Related pages
FAQs
Why can someone open a page but not the app embedded in it?
Page access and custom-app access are separate. Review the app’s sharing settings and give the person the appropriate app role.
What should I revoke when a tool should no longer access Bidlo?
Revoke the specific API or MCP key used by that tool. Separate keys for separate integrations make this possible without interrupting unrelated access.