KBAISE/ for lovable
Library
Docs

Privacy & security settings

about 15 minBuildingchecked 19h agoOfficial page
The short version

This page helps you control who can access your projects, publish content, and share information across your Lovable workspace. It also covers settings for security checks and how to manage old projects.

Workspace admins and owners need this when they want to set rules for how their team uses Lovable.

Do this, in order

  1. 1

    Go to your Lovable workspace settings.

    This is where all the privacy and security controls for your entire workspace are located.

  2. 2

    Navigate to 'Security' and then 'Privacy & security'.

    This specific tab contains all the settings described on this page.

  3. 3

    Review each section like 'Access & membership', 'Publishing', 'Security automation', 'Abandoned projects', and 'Sharing'.

    Each section controls different aspects of how your team interacts with projects and data, from who can join to how projects are shared and secured.

  4. 4

    Adjust settings according to your organization's needs, such as who can invite new members, if two-factor authentication is required, or if projects can be published with security issues.

    These adjustments ensure your workspace operates with the desired level of control over access, data, and security.

  5. 5

    Click 'Update' after making any changes to apply them.

    Most changes require you to save them before they take effect.

Paste this into your project

I need to manage who can access projects, publish content, and share information in my Lovable workspace. Can you guide me through the Privacy & security settings to set up default project visibility, control external sharing, and configure security automation?

Words decoded

Workspace
This is your team's shared area in Lovable where all projects and members are organized.
Two-factor authentication (2FA)
An extra security step, like a code from your phone, that you need to enter after your password to prove it's really you.
SSO (Single Sign-On)
A system that lets you log in once to one service (like your company's main login) and then automatically access other connected services (like Lovable) without logging in again.
PII (Personally Identifiable Information)
Any information that can be used to identify a specific person, like their name, email, or address.
RLS (Row-Level Security)
A way to control who can see specific rows of data in a database, ensuring people only see what they're allowed to.
JIT (Just-In-Time provisioning)
Automatically creating a user account in Lovable for someone the first time they try to log in, based on their company's identity system.
SCIM (System for Cross-domain Identity Management)
A standard way for different systems to automatically share user identity information, like creating, updating, or deleting user accounts.
Verified domain
An internet domain (like 'yourcompany.com') that your organization has proven it owns in Lovable, allowing for special controls related to users from that domain.

Where people get stuck

  • Forgetting to click 'Update' after changing settings, which means your changes won't be saved.
  • Not understanding that some settings, like 'Default project access' or 'Default website access', only apply to *new* projects and don't change existing ones.
  • Enabling 'Enforce SSO' will automatically disable 'Require two-factor authentication', as SSO providers usually handle multi-factor authentication.
  • Setting 'Who can publish externally' to 'Owners only' can prevent admins from changing this setting later, requiring the owner to relax the policy first.
  • Disabling 'External project collaborators' with the 'Remove all external collaborators' checkbox unchecked will make existing external collaborators lose access without being fully removed, potentially causing confusion.
  • Disabling 'Preview link sharing' when you still need to share in-progress work with external stakeholders.
  • Not realizing that 'Lovable workspace identity' is for apps to recognize logged-in workspace members, not a login button for the app itself.
  • Assuming that 'Block publishing with critical issues' means your app is fully secure; it only blocks publishing based on detected issues, and you should still test access rules.

The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.