Fluid Security
Keep the right people in control.
Every person, token, and app works through a role you define. People sign in with one-time codes, key records keep their history, and Mist works only within the access of the person asking.
Roles
Give every person exactly the access they need.
Start from a template, set each area to no access, view only, full, or custom, and search for the exact permission you mean.
- About 300 permissionsView, create, edit, and delete across more than 100 parts of the business, plus sensitive actions like revealing a login code.
- Templates to start fromFull Admin, Sales Manager, Content Editor, Support, Product Manager, Rep Manager, and Marketing.
- More than one role per personAn admin can hold several roles, and every admin needs at least one.
- Checked on the serverEvery request is checked against the role’s exact permissions, not just hidden in the interface.
Tokens and apps
Tokens and apps get roles too.
API tokens, partner tokens, and installed apps are limited by a role, can expire, and stay masked on screen.
- A role on every tokenChoose the role for each API token, and see at a glance which ones have none.
- Public tokens stay narrowA short list of read and upload scopes, limited to the domains you allow.
- Expiry datesSet when a token expires, or see which ones never do.
- Signed webhooksEvery delivery carries an auth token and an HMAC-SHA256 signature, and failed deliveries can be sent again.
Sign-in
Codes instead of passwords, and a record of every assist.
People sign in with a one-time code, or with Google, Apple, or Facebook. Support can help a member in, but only after confirming they have permission, and every time is logged.
- Short-lived codesSix digits by email or text, valid for 30 minutes, locked after five wrong tries.
- Rate-limitedRequests for codes and attempts to use them are throttled every minute.
- Your session lengthEach company sets how long a session lasts, from 1 to 720 hours.
- Assisted sign-in, on the recordRevealing a member’s code needs a confirmation, shows the code once, and logs the reveal.
History
See what changed, and put it back.
Website templates and portals keep versions, and key records keep an audit trail, so a change can be compared and rolled back.
- Template versionsEvery save becomes a numbered version you can compare with another and publish again.
- Portal snapshotsNothing reaches reps until a portal version is activated.
- Whole-theme restoreRestore a theme to an earlier published version, or keep it in sync with Git.
- Record historyOrders, subscriptions, discounts, pages, forms, inventory, and payment accounts keep a history of changes.
Mist
Mist works inside your permissions.
Mist uses the access of the person asking, asks before it creates anything, and can be kept away from production entirely. Every change it makes can be reviewed and reverted.
- Your access, not moreEvery call Mist makes carries the signed-in person’s token and role.
- Approval to createCreating something needs a one-time approval tied to the exact item, valid for 15 minutes.
- Safe ModeOne switch blocks every change to production while Mist reads and explores.
- Leaves with the personWhen someone’s access ends, Mist’s desktop app wipes that company’s local data and credentials.
What it replaces
Access you can see, instead of a spreadsheet about it.
Access reviews usually mean exporting users into a spreadsheet, chasing approvals, and collecting screenshots as evidence. In Fluid, roles, tokens, and history live where the work happens.
Usually
- Access-review spreadsheets
- Permission review workflows
- Approval evidence collection
- Manual control checks
- Custom roles from about 300 permissions
- Roles on tokens and apps
- One-time-code sign-in
- Logged support access
- Versions you can restore
- Mist within your permissions
FAQs
Questions security teams ask.
We’ll walk your team through the controls and how you’d use them.
How do people sign in?
With a six-digit code sent by email or text, valid for 30 minutes and locked after five wrong tries, or with Google, Apple, or Facebook.
Can one person have more than one role?
Yes. Admins can hold several roles, every admin needs at least one, and each request is checked on the server against the exact permissions.
How do you limit what integrations can do?
Every API token and installed app is bound to a role, can be set to expire, and is masked on screen. Public storefront tokens are limited to a short list of read and upload scopes and the domains you allow.
Can support staff get into a member’s account?
Only with the Reveal login code permission. The agent confirms they have the member’s permission, sees the code once, and every reveal is logged.
What can Mist do with our data?
Only what the person using it is allowed to do, because it works with their access. Creating things needs a one-time approval, Safe Mode blocks every change to production, and each change Mist makes can be reviewed and reverted.
Can we see what changed on the website?
Every template save becomes a version you can compare and publish again, and whole themes can be restored or kept in sync with Git.
Explore the platform
Protection across the platform.
The same roles and records carry through payments, content, and the tools your team builds.
See it with your team
Bring us your access list. We’ll show you who can do what.
We’ll map your team, your tokens, and your integrations to roles in Fluid with you.