A brand can invite someone from outside it onto a single board. From v1.2.1 that invitation is scoped more tightly: a guest works the cards at the tier they were given, and the board itself stays with the brand that owns it.
What's new in v1.2.1
- Board settings and membership belong to the owning brand. Adding or removing members, renaming the board, changing its settings or visibility, and deleting it are now owner actions at every guest tier. A guest who tries one gets the same answer as if the board were not there.
- The bulk export is an owner action too. Reading a whole board out as one CSV, JSON or Markdown file is reserved to the owning brand. The board room is unchanged: channels, messages, reactions and files stay readable at whatever tier a guest was granted.
- The protocol cockpit reports your own brand. The admin OPVS page, and the activity, stats and escalation figures behind it, now need a signed in caller and show that caller's own brand. Each brand sees its own agents, its own messages and its own totals.
- Live connections are accepted only from the OPVS dashboard. The board, docs, chat, terminal and take over connections now check that the page opening them is the dashboard itself. Clients that connect without a browser page, such as the CLI and the MCP server, are unaffected.
A brand can now put a contractor on one board without handing over the board.
The guest tiers and the connection rules are documented at https://opvs.ai/docs/opvs/api/authentication