Censerva
  • Changelog
  • Documentation
  • Pricing
  • FAQ
Censerva

Here you can add a description about your company or product

© Copyright 2026 Censerva. All Rights Reserved.

About
  • Contact
Product
  • Documentation
  • Pricing
Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
Changelog
Sep 5, 2026

Read-only access is now enforced by the database

A read-only role is now a real boundary rather than a hidden button, on every route into the system.

Read-only access used to be enforced by the application. Somebody with a read-only role saw no controls, and the application refused their changes — but the rule lived only in the paths that remembered to check it.

It now lives in the database. A read-only member cannot record a change by any route: not through the interface, not by calling the API directly, not from a device syncing work recorded elsewhere. Every operational record is covered, with no exceptions to remember.

Read access is unchanged. A read-only member still sees everything their membership allows, which is the point of the role.

Nobody was affected: there are no read-only members on any account yet. This closes the gap before the first one is invited.

Previous

Starting and finishing a move works again

Sep 5, 2026
Next

Session security is now yours to set

Sep 6, 2026