Skip to main content

Who can publish and open apps

In a workspace with more than one person, two questions matter: who may put a project on the web, and who may open it once it’s there.

Who can publish

Publishing needs the Editor role or higher. Viewers can’t publish. On Enterprise, an admin chooses a rule for the whole workspace in Team → Privacy & security → Who can publish: On Free, Pro and Business, Editors and up always publish directly. On Enterprise that is the default until an admin changes it. The same rule applies when the agent publishes for someone: it publishes as the person whose message it’s working on.

Publish approvals (Enterprise)

With Editors ask, an admin approves:
  1. The Editor clicks Ask an admin to publish in the Publish dialog. The dialog says it’s Waiting for an admin.
  2. The workspace’s Admins and owner get an email, and the request shows up in Team → Approvals (and as Review in the workspace menu).
  3. An admin clicks Approve and publish or Decline. Approving starts the publish right away.
  4. The Editor gets an email with the decision.
A project has at most one open request. Asking again updates it.

Members-only apps (Business)

A Business workspace can publish apps that only its members can open — internal tools, dashboards, admin panels.
  • Per app: in the Publish dialog, set Who can open it to Only workspace members (or Anyone with the link).
  • Default for new apps: Team → Privacy & security → Default website access → Workspace members.
When someone opens a members-only app, they’re sent to sign in to Mythex. If they’re a member of the workspace and can see the project, they’re let in; otherwise they’re told the app is only for members of the workspace that made it. A sign-in lasts 7 days on that app’s address. Someone removed from the workspace loses access within about a minute. Members-only works on both of the app’s Mythex addresses ({slug}.mythex.app and {slug}.mythex.ai) and on its custom domains. Publishing the app again keeps its access setting.
Members-only is about who can open the app. Your app’s own users and login (if it has one) are separate — see Security for your app.