Access and security model
Bstrapr manages the relationship between infrastructure owners, Sites, and the people they authorize.
Authentication and identity
Collaborators authenticate through Bstrapr before reaching Sites they have been assigned. Identity is separate from the access decision: being a team member does not automatically mean access to every Site.
Site-scoped authorization
The Site is the customer-facing access boundary. Owners grant access to specific Sites, which supports least-privilege decisions for external developers, contractors, and agency specialists.
- Owners can see who has access to each Site
- A collaborator can have one Site without another
- Provider groups support repeatable assignments for managed client Sites
Encrypted connectivity
Site connectivity uses encrypted private networking. Connectivity is one part of the model; Bstrapr also manages named collaborator identity, Site scope, and access lifecycle.
Revocation
When an owner revokes a grant or removes a person from a group, access derived from that relationship ends. The Site remains in place and under the owner’s control.
Isolation and visibility
Customer accounts and access relationships are isolated by tenant context. Bstrapr manages access relationships and enrollment state; application data and workloads remain on the customer’s infrastructure.
Access activity history
Owners can review who was granted access, which Sites they could reach, and when access changed. This is an operational access history, not a claim of formal audit-ready compliance packaging.
This public guide explains the workflow. Environment-specific setup commands, connection details, and administrative controls are available inside the authenticated dashboard.