Creating, editing, or deleting a site now requires a permission
SecurityCreating a site, saving changes on its General settings page, and deleting a site now require your role to grant the sites:edit permission. Previously, any signed-in member could do all three.
Without that permission: the site switcher's Create site item and the /dashboard/sites/new form no longer appear, and a site's General settings page opens read-only: the fields still show, but there's no way to save, and the delete option is gone. Viewing and navigating a site's workspace is unaffected; there's still no separate permission for that.
When this shipped, the permission wasn't yet offered as a checkbox in the role builder, so Admin was the only role that granted it. That gap was closed on 17 August 2026: any custom role can grant it now. See Roles for how permissions and custom roles work.
Resources
