What you're seeing
You open a page and see a "not allowed" or "forbidden" message, or you're silently sent back to the sign-in screen.
Why it happens
Ceum is single-user — everything you create belongs to just you — so there's no role hierarchy involved. The realistic reasons you'd see a permission error:
- Your session expired. You were signed out and the page couldn't continue.
- Wrong account. You're signed into a different account than the one that owns what you're trying to open. Easy to hit if you have more than one Ceum account.
- Opening something that isn't yours. You followed a link to an item that exists but belongs to another account — usually a stale link, a teammate's screenshot, or a hand-edited address.
- A revoked MCP token. A connected external tool is using a token that's been revoked or whose owner deleted their account. See CLI / MCP token issues.
- An integration calling something unavailable. The token works, but it's trying to use a tool that doesn't exist or has been turned off.
There are no admin pages in Ceum — references to "admin pages" in older content no longer apply.
How to fix it
- Check that you're still signed in. Open any other page. If you get bounced to the sign-in screen, your session lapsed — sign back in.
- Confirm the account. Open Account settings and check the email; you may be on a secondary account.
- Don't trust the link. If you arrived from a link someone else shared, the item likely belongs to their account, not yours. Use Search or the list pages to find items you own.
- For integration problems, see CLI / MCP token issues — the dedicated guide for rotating, revoking, and checking tokens.
Tips and edge cases
- A Ceum link someone sent you is not a share link. An ordinary app address points at a record inside the sender's own account, so opening it signed in as yourself gives exactly this error. Sharing does exist, but it works differently: the owner opens the item and presses Share, which creates a separate read-only link that needs no Ceum account. Ask them to send you that instead — see Share links.
- A share link only ever shows one thing, read-only. It covers a single invoice, task, kanban board, document, transaction, calendar, or generated export file. It is not access to the workspace: nothing can be edited through it, and nothing else in the account is reachable from it. For anything a share link does not cover, an export is still the way to hand data over.
- A share link can stop working. The owner can revoke it, and a link created with an expiry stops at that date. If a link that worked yesterday now shows an error, ask the owner to check it on their Shared data page rather than assuming your account is at fault.
- The MCP events log helps track down integration problems. If a connected tool is being rejected, check Sessions and MCP events for the last successful call to pin down when access broke.