What it means
A loam site has no users, roles or groups. A key belongs to a person or an agent, says what it may do, and carries the secret that proves it. The site keeps a fingerprint of that secret, never the secret itself.
How loam does it
A key's rights are a grid. Each cell is granted on its own, and none implies another.
- Four kinds of file. Content, templates, files and the guide — each with read, write and remove.
- Two rights on the live site. Publish, and take back. A key that may write but not publish can do real work and no harm.
- Read-only views apart. The journal, the form inbox, the plan, the list of keys — each granted separately. The inbox holds personal data and is given sparingly.
- Safe delegation. Nobody hands out more than they hold, and nobody manages a key beyond their own reach. Delegation can go several levels deep without the owner losing the top.
- Refusals that help. A request outside a key's rights is refused with the missing right named — so it tells you who to ask.
A copywriter writes content but does not publish. A design agency writes templates and nothing else. An auditor reads everything and writes nothing. A key is shown once; lose it and you make a new one. When someone leaves, you revoke theirs — nothing else needs cleaning up.
What it costs
You decide every key. The template right deserves the most thought: templates are code, so whoever may write them can make the site do anything. It goes only to people you fully trust. And a key is only as safe as the account behind the agent that holds it.