Business plan and above. Off by default — enable under Settings → Modules.
Limits access to your workspace to IP addresses and CIDR ranges you nominate —
office networks, a VPN egress, known client sites.
Setting it up
Enable the module, then add allowed addresses or ranges under the module’s
settings. Requests from anywhere else are refused.
Add your current address before enabling. A whitelist that doesn’t
include where you’re sitting will lock you out of your own workspace. If
you’re on a home connection with a dynamic IP, add the range rather than a
single address.
Remote and travelling teams
If people work from changing locations, put them behind a VPN with a stable
egress address and allow that, rather than maintaining a list of individual
addresses.
What it does and doesn’t cover
It governs access to the workspace’s data. It is a network-level control, not a
substitute for roles — someone on an allowed network still only sees the
projects they’re a member of.