Integrations
LiveDeveloper access model
Understand workspace, project, agent, and API-token authority
Overview
Taskcenter uses layered authorization. Organization isolation selects the tenant, workspace roles govern organization-wide capabilities, project membership governs human and project-agent access, and API-token scopes limit which operations a system actor may request.
Human access
Signed-in users receive an organization role and may also receive explicit project membership. Project routes resolve the organization and project before returning data. Owners and admins can manage workspace-level settings; project roles narrow what members can view, comment on, contribute to, operate, or manage. The public `/login` route submits credentials to the server-side auth routes, which read the real account and session records. Its right-hand artwork is decorative; it does not display sample customers or invented endorsements. When no account exists, sign-in reports the auth result rather than showing a sample workspace. On public hosts, Turnstile must complete before submission; an unavailable challenge shows a specific retry/error state. Local `next dev` may omit the widget only under the explicit loopback-only auth-preview flag. The isolated compiled Cloudflare preview has no Turnstile secret and an empty site key, so it offers no widget that the local server cannot require. This does not verify production Turnstile; production retains its real key and requires a separate live acceptance check.
Project agents
Project agents use explicit project membership roles such as owner, operator, contributor, and viewer. Their admitted toolset is intersected with stored membership policy and the exact project id. A project agent cannot use its profile to broaden an empty or invalid allowlist, and a mutation still requires the matching permission.
API tokens
API tokens are organization-scoped system actors carrying explicit scopes. Scope checks are enforced at route and tool admission, secrets are shown once, tokens can expire, and revocation is durable. The current limitation is important: tokens do not yet carry a project allowlist, so a token scope is not a project-level grant boundary.
Recommended policy
Create a separate token per integration, use the smallest scope list, set an expiration for third-party access, store the secret outside source control, send idempotency keys on writes, and revoke unused tokens. Use a human or project-agent membership when a workflow requires true project-level least privilege.
Auditability
Runtime mutations use the guarded data adapter with organization binding, feature-block identity, permission, target, and audit event metadata. MCP calls also write tool-call state. Authorization is deny-by-default; unavailable persistence is reported as unavailable instead of being represented as an empty data set.