Skip to content
AgencyOS
All features/Privacy by design
The problem

One wrong click, and the client reads what you wrote about them.

You decide what the client sees. The database makes sure of it.

In AgencyOS, every item, comment, feed entry and page is either shared or internal, and anything internal never reaches a client’s browser at all.

01 · Two layers

First the customer, then what’s shared.

The first layer decides what someone can reach at all: a client sees their own company and nothing else, and a client member sees only the projects named for them. The second layer is visibility. Within that reach, you decide for each thing whether it’s shared.

  • Make a work item internal and its comments, files and documents go with it.
  • Switch an item to shared and everything that was shared on it appears together.
Tim KrausClient member · Muster GmbH
Muster GmbH
Portal Relaunch✓
Infrastructure—
02 · Sensible defaults

Defaults that fit most cases.

A feed entry is written to the client, so it starts out shared. A document is usually written before it’s shown, so it starts out internal. A work item follows its project, which means an ops project stays internal without anyone deciding item by item.

  • Sharing a page or revealing an item asks first, because something seen can’t be unseen.
  • Only owners and employees decide what’s shared. A client never even sees the switch.
WhatStarts as
Work itemproject defaultSharedInternal
Commentlast used on the itemSharedInternal
Feed entrysharedSharedInternal
DocumentinternalSharedInternal
Time entryalways internalInternal
03 · Enforced underneath

Internal data is never sent.

The rule is written into the database itself, on every table, and anyone not explicitly allowed sees nothing. A screen that forgets to filter simply returns nothing, and a client asking for an internal item directly gets the same answer as for one that never existed.

  • A client is never told the switch exists, since their data carries no “internal” flag to notice.
  • Every visibility change is recorded: who made it, when, and from what to what.
GET/work-items/ops-22
What the client receives404 · the same answer as for an item that never existed
In detail

Five roles

Owner, Employee, Freelancer, Client admin and Client member. A client member reaches only the projects you name.

Project-scoped people

Narrow an employee, a freelancer or a client member to named projects. It takes effect on their very next click.

Links that follow the page

A public link never shows more than the client portal would, and stops working the moment the page goes internal.

Files follow their message

An attachment is visible exactly when the entry or comment it belongs to is.

Agents with limits

An AI agent decides nothing about visibility unless you allow it per token. Otherwise everything it adds takes the default.

Deactivation in seconds

Their sessions end immediately, and the person’s name stays on everything they wrote.

See it with your own customers in it.

We’ll set up your workspace with you and move your current projects over before the first call ends.