A close-up portrait of a man with a salt-and-pepper beard wearing a white collared shirt against a textured beige background.
A close-up portrait of a man with a salt-and-pepper beard wearing a white collared shirt against a textured beige background.

Access to one app

Jesse James Richard
|
Mar 20, 2026
|
4 min read
#Access Control
#Growth

A marketing agency runs six client accounts on Giant Context. For a product launch, they bring in a freelance copywriter for two weeks to write email campaigns for exactly one of those clients. The question that decides whether the agency can use my platform for real work is small and specific. Can they give that freelancer access to one email tool, on one client, and nothing else?

Yes.

One membership, scoped access

Everyone who works in an organization is a member of that organization. That part is not optional, because membership is the anchor for identity, billing, and the audit trail. What varies is how much of the organization your membership reaches, not whether you belong.

So the freelance copywriter is added to the agency's organization, but as a collaborator, the role built for exactly this, an outsider who works with the company without being of it. A collaborator sees nothing in the organization by default. Access is then granted one resource at a time, and the copywriter is granted one, the email app for that single client. That grant is the whole of what they can touch. The other five clients, the other tools, the billing, the other projects, none of it is hidden behind a permission error they can see the shape of. Ungranted, it is simply not there for them.

A member's permissions page, showing an organization role, a project beneath it, and eight apps each with its own role selector.
One person's access, set app by app. Editor on two, viewer on the rest, each granted separately.

Why coarse access fails

Coarse access is easy to build and useless in practice. A platform that only offers organization membership forces a choice every team hates. Either you hand an outsider the keys to everything, or you do not let them in and email them files like it is 2010. Neither is how work actually happens. Work happens in narrow, temporary, specific grants. This person, this tool, this client, these two weeks.

Granting access one resource at a time is what lets a customer describe their trust structure to the software instead of rounding it off. An agency's trust structure is genuinely complicated. Full-time staff who see everything, account leads who own one client, freelancers who touch one deliverable. App-level membership is the platform admitting that complexity is normal and giving it somewhere to live.

The market this opens

This is business logic rather than engineering, though the two are the same decision seen from different sides.

A platform that only serves one person per account has a ceiling. The market above that ceiling, the agencies, the teams, the companies with contractors, is where the real money and the sticky, hard-to-leave accounts are. But those customers cannot adopt a tool that makes them overshare access, because oversharing access is a liability they will not take on for a piece of software. The moment a platform can express this freelancer, this app, two weeks, it becomes usable by a whole tier of customer it could not touch before.

So app-level membership decides whether the product tops out at solo operators or grows into the accounts that run agencies. The narrow grant is what unlocks the wide market.

The agency brings the freelancer in for two weeks, the work gets done, and the access is gone when the engagement ends. The next time they need an outsider, they do not think twice about it. That is what makes an account hard to leave.

Where deleted things go

#Architecture
#Data

A customer deletes their homepage and it vanishes, but it is not gone. On a platform holding other people's work, delete is a state, not an act. Every...

Jesse James Richard

|

Mar 16, 2026
Read previous

Building something like this

I'm Jesse. I build platforms end to end, and I'm open to work. If this is the kind of engineering you need, get in touch.

Contact Jesse
Home
About
Contact
Sitemap
Privacy Policy
Terms of Service
Cookie Policy
Access to one app | Jesse James Richard