The right access for your team, your agency and
Claude
Every page shows who changed what and when, including when it was Claude. Sharing, exporting and assigning roles are permissions you grant one by one.
Workspaces that isolate data, roles defined by a super admin, two-factor authentication, your own domains with automatic TLS, and the controls from the September 2026 security release.
Many hands on the brand and no record
Marketing, branches, outside agencies and now AI assistants all touch what the institution publishes. In many tools anyone with access can edit, share or export, passwords get sent by email, and nobody knows who changed the promotion page. When compliance asks, the answer ends up being a search through the team chat.
Controls your IT team can review
Isolated workspaces
Each brand, country or company in the group gets its own workspace, with its own data, domains, themes, analytics, tags and users. One person can be an admin in one workspace and have no access in another.
Roles and separate permissions
A super admin decides what each role allows. Sharing with other workspaces, creating share links, exporting lists, exporting QR codes, assigning roles and viewing billing are separate permissions, and view-only roles can't change anything.
Two-factor and passkeys
Two-factor authentication with recovery codes, which your organization's admin can make mandatory. Once it's on, it's required before the panel, private pages and connecting Claude. People can also sign in with passkeys.
History under every page
Every page shows who changed what and when. Anything done through Claude appears under the person's name, marked as done via Claude, with the connection that made it.
Your own domains
Connect your domains with DNS validation and an automatic TLS certificate. A domain can be shared with other workspaces, and it can't be deleted while links, pages or sites depend on it.
Scripts and embeds
Tracking scripts run only where you attach them: a theme, a page or a site. Embed widgets accept approved services only, and every bulk import leaves a log with row-by-row errors.
What IT and compliance usually check
An agency with limited access
Invite the agency to a workspace with a role that edits pages but can't share with other workspaces, create share links or export. Accounts are created by email invitation, so nobody has to send them a password.
A group with several companies
Each company works in its own workspace. The group shares domains and brand assets read-only, and each company still sees only its own work.
The vendor security review
The September 2026 release bound every session to your organization's own address and added per-site rate limits, a temporary share-link lockout after 5 wrong passwords, and exports protected against formula injection. Private downloads use signed, short-lived links.
Claude with clear limits
Claude works with the permissions of the person who connects it. Changes it makes to themes, Brand Vault values or widgets on pages that are already public go live immediately. For strict control, give those people a role without those permissions.
Frequently asked questions
Yes. Each organization's admin in linkable.id can make two-factor authentication mandatory or leave it optional. Once it's on, the code is required before the panel, private pages, custom pages and connecting Claude. Each user keeps recovery codes and can also sign in with passkeys.
In the history linkable.id shows under every page: what changed, when, and who did it. If the change was made through Claude, it appears under the name of the person who asked for it, marked as done via Claude.
No admin ever sets a password in linkable.id. Accounts are created by email invitation and each person chooses their own; password resets also arrive by email. A super admin's account can only be edited by another super admin.
Yes. linkable.id validates your domain through DNS and issues the TLS certificate automatically. A domain can be shared with other workspaces and stays protected: it can't be deleted while links, pages or sites depend on it.
linkable.id bound every session to the organization's own address, added per-site rate limits, stopped the panel from being shown inside other websites, and locks a share link's password for a while after 5 wrong tries. Exported spreadsheets can no longer run hidden formulas, and view-only roles can no longer change what a record uses.
Does your IT team need to review the controls before deciding?
We will show you roles, permissions, two-factor authentication and the change history in a test workspace, and answer your security team's questions.