Access
Control who can view, create, review, approve, and publish through granular roles, permissions, SSO, and MFA.
A headless platform where business teams publish visually, and developers build anything from your main site to your intranet, using any front-end framework.










Take a Virtual Tour of dotCMS
dotCMS enforces governance at the platform level. Granular access, approval workflows, audit trails, version history, rollback, and independent certifications give compliance-led teams the control they need to move faster.
Control who can view, create, review, approve, and publish through granular roles, permissions, SSO, and MFA.
Maintain a complete audit trail showing who changed what and when.
Compare versions, require approval before publishing, and roll back changes when needed.
Meet security and AI governance requirements with ISO 27001, ISO 42001, SOC 2 Type II, and TX-RAMP.
See how dotCMS fits the workflows, experiences, and operational realities of your sector.
websites
dotCMS powers over 500 websites for one of the nation's largest healthcare providers.
From visual authoring to global delivery, dotCMS brings every site and content operation under one set of roles, workflows, permissions, and audit trails. Deploy on-prem, in your cloud, or in ours.
Give developers the freedom to use their preferred front-end frameworks while content teams create, preview, and manage experiences visually.
Meet infrastructure, security, and data-residency requirements without locking your content strategy into one deployment model.
Enforce roles, permissions, approvals, audit trails, and version history across every site and every person or AI agent acting on your content.
Use analytics, testing, and personalization to improve performance without bypassing the workflows and controls protecting your content.
Give developers the freedom to use their preferred front-end frameworks while content teams create, preview, and manage experiences visually.
Meet infrastructure, security, and data-residency requirements without locking your content strategy into one deployment model.
Enforce roles, permissions, approvals, audit trails, and version history across every site and every person or AI agent acting on your content.
Use analytics, testing, and personalization to improve performance without bypassing the workflows and controls protecting your content.
AI agents operate in dotCMS as actors with assigned roles, permissions, workflows, and audit trails. They draft multi-step work, but the approval process still determines what reaches production and every action remains traceable and reversible.
Use approved models and cloud providers while keeping AI activity inside your established governance model.
Keep AI-assisted actions visible, attributable, reviewable, and reversible.
When a role requires human approval before publishing, the agent follows that requirement too.
Assign an agent a dotCMS role and limit its actions through the permissions associated with that role.
Whether you are validating the architecture, exploring a focused use case, planning a migration, or preparing for implementation, choose the path that matches your evaluation process.
Business Source License is free for non-production use.
Enterprise grade CMS for intranets and portals.
REST and GraphQL APIs, SDKs, and integration guides for developers.
Structured migration from assessment to go-live.
Certified implementation partners to help plan, build, and launch.
Ship modern front ends with headless APIs - while dotCMS handles multi-site scale, governance, and enterprise deployment needs.
REST and GraphQL for any front end and any channel.
React, Next.js, Angular, Vue - bring your stack.
CI/CD-ready workflows for predictable releases.
Run many sites from one platform with shared models and controls.
Local dev tools, scaffolding, and automation for faster builds.
Structured content types with relationships for reuse at scale.
Create, approve, and publish updates visually - with workflows and permissions that keep compliance-led teams safe.
Edit in-context on real pages without breaking headless delivery.
Drag-and-drop components with real-time preview.
Publish once across sites, portals, and experiences.
Multi-step reviews for legal, brand, and compliance teams.
Target content by audience, location, or behavior.
A/B test content and iterate with confidence.
Enforce access, accountability, approval, and recovery requirements across every site and every action.
Know who changed what, when, and why.
Prevent content from going live until required reviews are complete.
Granular permissions and role-based publishing.
Apply the same roles, permissions, workflows, and auditability to AI-assisted work.
Scale across high-volume environments.
Cloud, on-premise, or Cloud Anywhere based on policy.



In the IDC MarketScape: Worldwide AI-Enabled Headless CMS 2025 Vendor Assessment
See how dotCMS empowers technical and content teams at compliance-led organizations.
dotCMS is ISO 27001 and ISO 42001 certified — The first and only CMS platform with independently verified security and AI governance.