The right documentation to the right people
Public help centre, partner-only portal and internal runbooks in one workspace - with permissions that AI search obeys as strictly as the navigation does.
- SSO on every paid plan
- Per-category permissions
- Permission-aware AI
How does access control work in TheDocs?
Each project sets an audience - public, sign-in required, or restricted to named accounts or email domains - and individual categories can be narrowed further. People are given roles per project and per category: owner, admin, author, reviewer or reader. Authentication can use email and password, SAML 2.0 or OIDC single sign-on, with SCIM provisioning on Enterprise. Every permission change is recorded in the audit log, and AI retrieval is filtered by the same rules before any answer is generated.
- Public, sign-in required, or named-account audiences per project.
- Category-level overrides for both readers and authors.
- Roles: owner, admin, author, reviewer, reader; custom roles on Enterprise.
- SAML 2.0 and OIDC from the Growth plan; SCIM on Enterprise.
- Optional SSO enforcement that disables password sign-in entirely.
- AI answers are grounded only in articles the reader may see.
Common configurations
Most customers end up running two or three of these side by side.
Fully public help centre
Indexed by search engines, open to everyone, no sign-in. The default for customer-facing documentation.
Customer-only documentation
Sign-in required through your identity provider or a shared reader account, noindexed, still fully searchable for those who can see it.
Partner portals
Restricted to named accounts or email domains, so each partner sees only their own integration documentation.
Internal wiki
Private to your organisation via SSO, with department-level category permissions for HR, finance or security content.
Mixed audience in one project
A public help centre with a few categories - billing internals, escalation paths - visible only to signed-in staff.
IP restriction
Limit a project to your office or VPN ranges, on its own or on top of sign-in.
The details that decide a security review
Identity done properly
Access control is only as good as the account lifecycle behind it.
- SAML 2.0 and OIDC with Okta, Entra ID, Google Workspace, JumpCloud, Auth0 and any standards-compliant provider.
- SSO enforcement disables password sign-in so there is no side door.
- SCIM 2.0 provisioning on Enterprise - a leaver deactivated in HR loses access immediately rather than eventually.
- Group-to-role mapping, so permissions follow your existing directory structure.
- Separate identity configuration for authors and for readers, which matters when readers are customers.
Permissions the AI cannot route around
A retrieval system that ignores permissions is a data leak with a friendly interface. Filtering happens before generation, not after.
- The candidate document set is narrowed to the reader's permitted articles before retrieval runs.
- Citations can therefore only ever point at articles that reader can open.
- The chatbot inherits the same rules - anonymous visitors get public content only.
- Search-gap analytics record the question but never leak the restricted content that would have answered it.
This is worth testing during your trial: sign in as a restricted reader and try to get the AI to answer from something they should not see.
Evidence and review
Access reviews are a recurring chore. Making the data easy to pull is most of the work.
- Every permission grant, change and removal logged with actor and timestamp.
- Per-user view: everything this person can see and edit, across all projects.
- Per-project view: everyone with access and how they got it - directly or through a group.
- Export any of it as CSV or through the API for your access review cycle.
Related features
Questions people ask before they start
Run your public docs and your internal runbooks from one workspace.
Start free for 14 days. No credit card, no setup fee, and your content is yours to export at any time.
Questions first? Email sales@thedocs.in or call +91 8585953085.