← Blog

What's new in Squidler

The apps your agent builds can now have users and roles

October 9, 2026 · 4 min read

Ask your agent for an app where some people may edit and others may only look, and it builds exactly that: people sign in, each one gets a role, and the platform holds every role to its rules. We asked Eleanor for a shared to-do list.

Squidler agents have been building small apps for a while: a booking page, a training calendar, a shared shopping list. Until now, though, an app could only tell people apart in one way. If you wanted to let someone into a private app, you made them a member of your agent, and a member can do everything: chat with the agent, use its desk, spend your quota and change anything in any app it built.

That is fine for the two or three people who work with your agent every day. It does not work for the sixty coaches who need to read a training calendar, or for the volunteer who should be able to tick off tasks but not delete the list.

So apps can now have their own users. People sign in to just that one app, and each person gets a role, such as editor or viewer. The app is built around those roles, and the platform holds every role to its rules.

One sentence

We hired a new assistant, Eleanor, and gave her one sentence to work with.

Eleanor's chat. The message reads: "Build an app for handling TODO lists. It should be possible to handle multiple lists. There should be two types of users: editors and viewers." Eleanor is thinking.
The whole request, in one sentence.

She replied with a plan, which already had the parts that matter: editors who can change things, viewers who can only look, and the rule that this is enforced by the platform itself, not just by hiding buttons. People she invites sign in, and they get no access to Eleanor herself, to her desk or to your quota.

Eleanor's reply: she has started building the app. Multiple lists; editors can create, rename and delete lists and change any item; viewers can see everything but can't change anything, enforced by the platform, not just by hiding buttons; live updates; sign-in for invited people only, who don't get access to her, her desk or your quota.
Eleanor's plan, before a line of code: what each role may do, and who enforces it.

Live, and tested

Then the app was live, on an address of its own. Before reporting back, Eleanor had opened it as an editor and as a viewer and checked what each could do. As a viewer she also tried changing the data directly, behind the app's back, and the server refused every attempt.

Eleanor's message: "TODO Lists is live: todo-lists--eleanor-squidler.squidler.app", listing lists, items with due dates, safe deleting, live updates, private, installable, and her test results. Beside the chat, the app's page on Eleanor's desk: Private, Open live app, Copy link.
Live on an address of its own, tested as both roles.

Every new app now gets an address like todo-lists--eleanor-squidler.squidler.app. That keeps it apart from squidler.io: your Squidler login never reaches the app, and each app keeps its own sign-ins. It can also be installed on a phone as an app in its own right.

Who gets in, and as what

Each app with users has a page of its own for people and roles. It lists the roles the app has, with what each one may do, and everyone who has access. You invite people one per line, with an email address and optionally their roles, and change a person's roles by ticking boxes.

The People and roles page for TODO Lists: 1 of 1000 places used. Roles: Admin, Editor and Viewer, each with what it may do. People: Erik Ogenvik as admin through the agent, and Erik Ogenvik with Viewer ticked. An invite box containing "adam.example@gmail.com - Editor".
Who can use the app, and as what. Email addresses blurred.

Here, Erik is in twice. The first is the account that owns Eleanor: people who work with your agent are always admins of its apps. The second is his own private address, invited as a viewer so that we could see what a viewer sees.

Invited people get an email with a link to the app. They sign in with Google, Microsoft, X or an email address and a password, and they land in the app. Anyone who already has a Squidler account is let in straight away and told so by email.

You don't have to use the page at all. "Make anna@example.com an editor" in the chat works just as well. The roles themselves are part of the app, so adding a new kind of role is something you ask the agent for, since the app has to be built around it.

The same app, twice

This is what Erik sees as an admin: the list, a field for new items, and ways to rename, reorder and delete.

The TODO Lists app signed in as an admin: a list called Renovate bathroom with the item Call contractor, an Add an item field with a date, Rename and Delete, arrows to reorder and buttons to edit and remove. At the bottom: Erik Ogenvik, ADMIN.
Signed in as an admin: everything can be changed.

And this is the same list for the viewer. There is nothing to add, edit or delete, and the corner of the app shows who is signed in and with which role.

The same app, installed as its own window at todo-lists--eleanor-squidler.squidler.app and signed in as a viewer: the list Renovate bathroom with Call contractor, and no fields or buttons to change anything. At the bottom: Erik Ogenvik, VIEWER.
The same list for a viewer: read-only, in the app and on the server.

The missing buttons are only the visible half. The rules are checked by the platform on every request. A viewer who tried to get around the app would be refused by the server, and the app is told that the change was refused, so it can say so. Changes appear for everyone without a reload, and each person only ever receives what their role may see.

What it costs you

Nothing extra. People who sign in to an app are not members of your agent: they cannot chat with it, they do not see its desk, and they do not use your quota. Each app has room for 1,000 people.

An app can also be open to requests instead of invitations: someone signs in, asks for access, and the app's admins approve or decline. Or it can let in anyone who signs in.

Apps you already have

Apps built before this keep their old address on squidler.io. To give one users and roles, ask your agent; it first moves the app to an address of its own. You can also do that yourself, from the app's page under Sharing & publishing. The old link keeps working and forwards to the new address. Anything the app stored in people's browsers starts empty at the new address, and anyone who installed it on their phone needs to install it again.

Where to find it

Just ask your agent for an app, and say who should be able to do what. Once an app has users, People and roles appears on the app's page.