When your agent builds and publishes a website or app for your team, you can now decide exactly who is allowed to open it. Lock a site down to a list of people you choose — everyone else is turned away at the door.
How to lock down a site
You set this up from the Layups admin site — you'll need to be an owner or admin of your organization. The whole thing takes about a minute. The one thing to get right: add the people first, then turn protection on.
Sign in at admin.layups.ai, then go to admin.layups.ai/capabilities/cloudflared.tunnels/domains. (The page is titled “Site publishing” — that's the right place.) You'll see every domain your agents publish to. Click the one you want to protect.
Find the “Zero Trust” box on the domain page. Type the email addresses of everyone allowed in — paste several at once, separated by commas or spaces — and click “Add.” The “Enable protection” button stays greyed out until at least one person is on the list, so always add people before the next step.
Now click “Enable protection.” The badge flips from “Public” to “Protected,” and from that moment only people on your list can open the site — everyone else is turned away. Each visitor signs in with a one-time code sent to their email; there's no new password to create.
Need to let someone go? Click the ✕ next to their email and they lose access right away. Want the site open to everyone again? Click “Make public.” Want one specific page to have its own separate list? On the same domain page, scroll to the “Sites” section, click “Access” next to that page, and build its allowlist there — it overrides the domain default for that page only.