Skip to content

Access Control

Access control starts at authentication and continues through every request.

  • Every API request requires a bearer token issued at sign-in.
  • Accounts can enable multi-factor authentication (MFA).
  • Administrative actions require an admin role in addition to a valid session.

Accounts carry one of three roles:

Role What it can do
admin Full access, including administrative surfaces
reviewer Review and act on bids and submissions, without administrative access
read-only View, but not change

Your company’s administrator assigns roles to your team’s accounts.

Endpoints are rate limited per account, with backoff signaling in the response. This protects the platform from abusive traffic without slowing normal work.