Invitation-only registration
Every account begins with an expiring, one-time invitation bound to an email address and a specific platform or tenant role.
Security
Couati is designed as a managed platform: no open signup, no anonymous tenant creation, and no hidden operator changes.
Every account begins with an expiring, one-time invitation bound to an email address and a specific platform or tenant role.
Organizations own isolated sites. Owner, administrator, editor, and viewer permissions are checked again at each site route.
Platform operators use time-based authenticator verification, while authoritative session controls support immediate revocation.
Commercial lifecycle, entitlements, invitations, account state, and security actions leave a timestamped audit record.
CSRF validation, rate limiting, secure cookie settings, restrictive headers, trusted proxy configuration, and production config checks are built in.
Database and Redis readiness, publishing jobs, audit history, and active sessions are visible to the right operators.
Governance model
Private access
Share your model, team, and launch goals. We will review the fit before issuing an invitation.