Panel
The client panel from the inside
Who approves a release, what stays on record and how long each access lasts, read from the code that runs.
Written by Matheus PavaneliPublished Oct 8, 2026Reviewed Oct 8, 20261 minRunning system
Download as MarkdownTwo ways to approve
Each client chooses who decides. In client mode a release waits for the client's own approval, and the admin cannot publish without it. In house mode the admin approves and publishes, and the client cannot publish.
How a client gets in
There is no self sign-up. The admin creates the client and the invite. The invite works once, and its token is kept only as a hash.
how to check: packages/portal/src/invites/inviteStore.ts, INVITE_LIFETIME_MS
After that the client signs in by a link sent to the e-mail, with no password, and a passkey is offered after the first access.
how to check: apps/portal/src/auth.ts, MAGIC_LINK_SECONDS
What stays on record
Activity is append-only: the database refuses to change or delete a line, and each record carries a protocol number.