Authentication And Access Policy
Last updated: July 23, 2026
Owner Access
The owner dashboard is protected by backend credentials stored in the private VPS environment file. Coolify deploys the app; it is not responsible for verifying clients or storing client passwords.
Client Access
Clients are created by the owner/admin inside the backend. The owner can search by client email and generate a temporary passcode for the private report link.
First Login
Clients must enter their email and temporary passcode, then create a new password before their report opens.
Provider Settings
Only the owner dashboard can change LLM provider order and model settings. Clients cannot view or change provider settings. Provider API keys stay in the private VPS backend file.