---
description: Studio roles, authentication, sessions, Cloudflare Access, and the separate Operations boundary.
---

# Access Control

Studio checks identity, role, resource ownership, and service state before
allowing an action. The Worker API enforces these checks; hidden navigation
alone does not protect a resource.

## Find a Policy

| Topic | Documentation |
| --- | --- |
| Password acceptance, mandatory MFA, and attempt limits | [Authentication](authentication/index.md) |
| Authenticator timing and one-use codes | [TOTP Verification](totp-verification/index.md) |
| Passwordless sign-in, hostname scope, and credential names | [Passkeys](passkeys/index.md) |
| Five-session limit, expiry, and revocation | [Sessions](sessions/index.md) |
| Fixed roles and content ownership | [Roles & Capabilities](roles-and-capabilities/index.md) |
| Lost factors or administrator access | [MFA Recovery](mfa-recovery/index.md) |
| An additional Cloudflare identity gate | [Cloudflare Access](cloudflare-access/index.md) |
| Major actions and retained connection information | [Audit Log](audit-log/index.md) |

## Authorization Layers

1. A valid session identifies an active account and its authentication revision.
2. Its fixed role grants the required capability.
3. Resource ownership can narrow that permission. An Author can manage only
   Posts belonging to the public Author linked to that account.
4. Database state, bindings, and integration settings determine whether the
   service can perform the action.
5. Mutations verify origin, CSRF proof, and any required reauthentication.

Unknown roles and unsupported capabilities are denied. An Administrator has
all Studio capabilities but does not bypass lifecycle or infrastructure checks.
Every active role can use its capability-filtered Dashboard, account security,
session management, and interface preferences.

## Operations Is a Separate Boundary

[Maintenance & Recovery](../operations/maintenance-and-recovery/index.md) requires
its own exact-IP allowlist and Operations token. In operational mode, an active
Studio administrator session is also required. Maintenance and recovery have
explicit workflows for cases where normal authentication is unavailable.

Cloudflare Access may restrict entry before either boundary. Requiring Access
inside Studio adds verified assertion checks; it does not grant a Studio role
or an Operations token.
