# For tech teams

> You're accountable when non-technical colleagues build on the company Airtable. VibeKit gives you control — one place to see who has access, revoke anyone without breaking a shared key, and an audit trail when something goes wrong.

When colleagues who don't write code build apps on the company Airtable, you're the one accountable
for it — and usually the one who ended up handing round the API key everyone now shares. That key is
the problem: it can't be scoped, it can't be revoked without breaking everything, and once it's out
you can't get it back.

VibeKit replaces the shared key with control. Everyone builds through the proxy instead of against
the base, so access is something you can see, scope, and take away — and nobody ever holds the raw
Airtable token.

## One place to see who has access

Every project and person goes through the proxy, so there's a single place to see who can read or
write which records — instead of guessing who has a copy of the key. The token itself stays
server-side in the [token vault](/products/vibekit/features/secure-token-vault).

## Revoke one person, not everyone

No shared key means no all-or-nothing. Remove one person's access and everyone else keeps working;
the credential never moved. Access can also be scoped per user right down to their own records with
[record-level security](/products/vibekit/features/rls-security).

## An audit trail when it matters

Every request is [logged](/products/vibekit/features/request-logs) against the person who made it, so when something
goes wrong you can see exactly what happened and when — not reconstruct it from guesswork.

## Features that matter most here

- [Your Airtable API token, kept secure server-side](/md/features/secure-token-vault.md) — Keep your Airtable token out of your website code entirely, so it can never leak to visitors.
- [A log of every Airtable API request](/md/features/request-logs.md) — Airtable gives you no logs for individual API calls; the proxy records every one, so you can audit access, catch anything unsafe, and see who's using your API and how much.
- [Record-level security for your Airtable data](/md/features/rls-security.md) — Each user only sees their own records — record-level security enforced on the proxy, like Supabase's row-level security.
- [Authentication and login, backed by Airtable](/md/features/airtable-auth.md) — Add real login to your app with your Airtable as the only user list you ever maintain.

## Questions this page answers

- give a team access to airtable without sharing the key
- control who can edit the company airtable
- revoke airtable access without breaking the app
- audit trail for airtable api access
- govern airtable access across a team

---

Part of [VibeKit](/md/home.md) — all pages: [llms.txt](/llms.txt)
