For enterprise
Control, without slowing anyone down
The Business plan adds the administrative surface larger organisations need — member provisioning, an audit trail and an SSO-ready identity layer — while the editor stays exactly as fast.
SSO-ready architecture
Identity is a separate provider layer, so SAML and OIDC connect without touching your data model.
Member provisioning
Invite, promote, demote and remove members; ownership transfers cleanly when people move on.
Audit trail
A record of map, membership and permission changes, with actor and timestamp.
Server-side authorisation
Every request is authorised centrally. The interface reflects permissions; it never decides them.
Data portability
Export any map as JSON, Markdown, PDF, SVG or PNG. Your content is never locked in.
Multiple workspaces
Separate spaces per department or client, each with its own members, plan and maps.
A permissions model you can explain to a security reviewer
Access resolves through one module. A request carries a user, a resource and a capability; the answer is computed from ownership, explicit membership, workspace membership and link settings — and the highest of those wins.
- Four map roles: owner, editor, commenter, viewer
- Three workspace roles: owner, admin, member
- Link access can be off, view, comment or edit
- Unauthorised reads return "not found" rather than leaking existence
- Share links can be rotated, instantly invalidating the previous one
Operational characteristics you can plan around
Untangling runs as a standard Next.js application plus a stateless collaboration service. Both scale horizontally; Redis coordinates presence across instances.
- PostgreSQL for durable state, Redis for presence and rate limits
- Collaboration state persists as a compact CRDT update per map
- Rate limiting on authentication, uploads and AI endpoints
- Uploads validated by size and MIME type, served with a restrictive content policy
- Deployable to your own infrastructure
Your content is not training data
AI features send only the text you explicitly submit, only when you trigger them. We do not train models on your maps, and the provider is configurable — including running against your own endpoint.
- AI calls are opt-in, per action
- Provider abstraction supports Anthropic, OpenAI or a self-hosted endpoint
- Per-workspace AI usage accounting
- No background processing of your content
Talk to us about a rollout
Start on Business and we will help with provisioning, identity and migration from whatever you use today.
Get started