Security

Private access and accountable operations by default.

Couati is designed as a managed platform: no open signup, no anonymous tenant creation, and no hidden operator changes.

Request access Client sign in
01

Invitation-only registration

Every account begins with an expiring, one-time invitation bound to an email address and a specific platform or tenant role.

02

Tenant isolation and scoped roles

Organizations own isolated sites. Owner, administrator, editor, and viewer permissions are checked again at each site route.

03

Authenticator-protected access

Platform operators use time-based authenticator verification, while authoritative session controls support immediate revocation.

04

Auditable operator controls

Commercial lifecycle, entitlements, invitations, account state, and security actions leave a timestamped audit record.

05

Protected web delivery

CSRF validation, rate limiting, secure cookie settings, restrictive headers, trusted proxy configuration, and production config checks are built in.

06

Operational visibility

Database and Redis readiness, publishing jobs, audit history, and active sessions are visible to the right operators.

Governance model

Who can change what

Platform administratorTenant lifecycle, plans, entitlements, invitations, global users, audit, system deliveryTenant owner / adminSites, team workflow, domains, themes, navigation, presentation, publishingEditorArticles, brands, categories, pages, media, evidence, tracked destinationsViewerRead-only workspace and operational visibility for assigned sites

Private access

Build the publication as a system.

Share your model, team, and launch goals. We will review the fit before issuing an invitation.

Request an invitation