Skip to main content
Security

Built to keep each group’s private data separate.

Golbi is designed for groups that handle families, children, dues, files, checklists, and staff tasks. It is not a public social feed. Private data should only be seen by the right people.

Security model

The key rule: each group is separate.

Groups stay separate

Each group has its own records. One group should never be able to see another group's data.

Clear access rules

Owners, admins, staff, coaches, guardians, volunteers, students, and members should see different things. Private tasks need clear approval.

Audit history

Important admin actions should leave a history record. This matters most for dues, checklist reviews, files, invites, and settings.

Sensitive tasks

Dues and checklists are private by default.

Members must not see another member's balance, payment status, waiver, or payment history.
Coach training uploads, review notes, waivers, and due dates are private data.
Member and coach pages should show only that person's information, or their family's information.
Member-only pages, private files, and chat rooms need server-side access checks.
Rosters should use simple labels, like eligible or not eligible, when details are not needed.

No overpromising

Golbi should not claim SOC 2, HIPAA, PCI, or other formal security reviews unless they are done. Security pages should say what works now and what is planned.

Signing in

One less password for parents, coaches, and volunteers.

You don't need a Golbi password. You sign in with a secure link sent to your email — a password is optional if you want one.
Each sign-in link works one time and expires, so an old email link can't be reused.
The link proves you own the email address it was sent to.
We limit how often links can be requested to slow down abuse.
For groups that require extra protection, Golbi can still ask admins for a second step, like an authenticator code, after you sign in.

What a link does and doesn't do

A sign-in link confirms who you are. It does not decide what you can see or do. Your role and the group's rules still control access, and private records stay protected by the same checks whether you use a link or a second step.

Forms and files

Public forms and private files need different rules.

Public forms

Forms need checks, spam protection, safe display, version records, and group limits before they collect real data.

Private files

Files should stay private unless an admin chooses to share them. Public site images should be chosen on purpose and tracked where they are used.

Messages and payments

Golbi does not store bank, card, or Venmo passwords. Chat and announcements must protect minors, private files, and member-only content.

Security should be part of the way your group works.

Set up the basics now and bring your team in when you are ready.