Skip to content

Who can publish and change a website

Workspace roles, API keys, connected apps, Benchy and guests, and the record of who changed what.

Workspace roles

A website belongs to its workspace, so a person’s role in the workspace decides what they can do with it.

RoleWhat they can do
Can viewSee the workspace’s websites, their versions, previews, domains and history
Can editAlso reserve names, publish previews and live versions, roll back, unpublish, connect and remove domains, edit content, read and export form entries
OwnerAlso delete a website, and connect GitHub for the workspace

API keys and connected apps

A key or connected app reaches the one workspace chosen when it was made, and never does more than the person it belongs to could. Make keys in Benchy Studio under Profile, then API keys; see Connect your agent.

CredentialWhat it can do with websites
API key with Read accessSee websites and their versions
API key with Publish websites accessSee websites; publish, preview, roll back and unpublish. Nothing else: it can’t reserve a name, connect a domain, change content or publish a canvas. It can be limited to one website, and then sees only that one
API key with Read and write or Ask me each time access, or a connected appEverything a person with Can edit can do through the tools, except deleting. With Ask me each time, every change waits for your approval in Studio
  • Use a Publish websites key limited to one website for the CLI, a build script or GitHub Actions, so a leaked key can only publish that site.
  • Revoking a key or disconnecting an app stops it at once, mid-deploy included.
  • No key or app can delete a website. That is done by the Owner, in Studio.

Benchy

Benchy acts for the person who asked, with that person’s role. Every publish, rollback and unpublish Benchy makes asks first, on a card naming the website and the address that changes, and “Always allow in this chat” never covers going live. Benchy never connects or removes a custom domain: a person decides where a website answers.

Guests

Guests work on one project or chat, not the workspace, so they can’t publish, change or see its websites in Studio. They can open any preview or live address you share with them, like anyone else.

Who did what

A website’s history records every deploy, rollback, unpublish, domain change and content save with the person, and what it came through: Studio, Desktop, the CLI, a named key, a connected app, or Benchy on their behalf. See Versions and history.

Use ← and → to move between pages.