Edit sites now also covers Languages, Branding, Public access, and onboarding review
SecurityEdit sites, since 6 August 2026, gated General settings: renaming a site, changing its platform or URL, editing its assistant context, deleting it. Four other places that write the same kind of data were checking only that you belonged to the organization, not that your role actually granted Edit sites:
- The site's Languages, Branding, and Public access settings pages.
- The "Here's your assistant" review screen you land on after onboarding's analysis finishes, and its fallback screen when we couldn't read your store.
A member holding a custom role without Edit sites could still save a language change, upload a logo, flip on the public link, rotate its key, or edit the allowed-origins list. That's fixed: every one of those saves now checks the permission, the same way General already did.
You'll notice this if your organization uses custom roles: a member without Edit sites no longer sees Save buttons on Languages or Branding, and the public-access toggle, key rotation, default-agent picker, and origin list on Public access disappear rather than sit there doing nothing. The review screen's Site name, What you sell, Tone of voice, and Language rows follow the same rule, except Assistant name, which needs Edit agents instead, since saving it mints a new agent version rather than editing the site.
Nothing changes for Admin, and nothing changes if your organization hasn't built a custom role that leaves Edit sites out.