WebSG Custom (Formerly Optical)
FAQs
Overview
How It Works
Features & Roadmap
Getting Started
Roles & Responsibilities
Resources
FAQs

FAQs

  1. What is WebSG Custom?

    WebSG Custom is an enterprise-grade Content Management System (CMS) built for Singapore Government agencies. It enables agencies to manage and publish content through a central platform, while keeping the content management backend separate from the frontend website.

    WebSG Custom is built on the open-source Directus platform and is designed to meet Singapore Government security and compliance requirements.

  2. Do I need design or coding skills?

    No coding skills are required for day-to-day content management. WebSG Custom provides a user-friendly interface for content teams to create, edit, preview, and manage content.

    However, developers are required to build the frontend website and integrate it with WebSG Custom through APIs.

  3. What can I use WebSG Custom for?

    WebSG Custom is suitable for agencies that need a flexible and scalable platform to manage content for websites and digital services.

    • Supported: Content management, structured data, media and file management, APIs, content preview, versioning, and role-based access.
    • Not Supported: WebSG Custom does not build the frontend website for you. The frontend presentation and any custom business logic will need to be developed separately.
  4. Is WebSG Custom secure and compliant with Government requirements?

    Yes. WebSG Custom is designed for Singapore Government use and comes with security and compliance capabilities such as TechPass authentication, malware scanning, activity tracking, and audit logs.

  5. Can WebSG Custom support high-traffic websites?

    Yes. WebSG Custom is designed for enterprise-scale use and supports capabilities such as autoscaling, caching, and Content Delivery Networks (CDN) to help websites handle high traffic reliably.

  6. Can I control who can manage or publish content?

    Yes. WebSG Custom supports Role-Based Access Control (RBAC), allowing teams to define different permissions for users such as content editors, reviewers, and administrators.

  7. Can WebSG Custom integrate with other systems?

    Yes. WebSG Custom provides APIs that developers can use to retrieve and manage content, allowing the frontend or other applications to consume content from WebSG Custom. It can also integrate with other services within the SG Tech Stack.

  8. Can I preview and track changes to my content?

    Yes. WebSG Custom supports content previews, versioning, and revisions, allowing content teams to review changes and manage different versions of their content before publishing.

  9. Can we use our own custom domain, and who handles the SSL certificate?

    Yes, you can use your own custom domain.

    • Domain Procurement: Your agency (e.g., via IMDA) is responsible for purchasing and owning your custom domain.
    • Domain Mapping: During onboarding, the WebSG Custom team will generate CNAME records. You will then need to log in to ITSM to complete the DNS mapping.
    • SSL Procurement & Renewals: WebSG Custom handles SSL certificate procurement and management. SSL certificates are provisioned and automatically renewed via AWS on your behalf.

      Note on Certificate Validity:
      SSL renewals are managed via AWS. We expect AWS to update its certificate rotation policy to meet the industry's 47-day certificate validity standard well ahead of the 2029 deadline.

  1. Who can use WebSG Custom?

    WebSG Custom is available to Singapore Government agencies. Public Officers and authorised vendor developers who require access to the CMS will need a valid TechPass account.

  2. How do I log in?

    WebSG Custom uses TechPass for authentication. Ensure that all Public Officers and vendor developers who require access have an active TechPass account.

    If you are new to TechPass, refer to the TechPass User Onboarding & Sign-Up Guide to create an account.

  3. How do I onboard SHIP-HATS?

    Agency Product Managers (PMs) or Points of Contact (POCs) may request SHIP-HATS onboarding directly via Techbiz Portal.

    Tenant or web developers requiring licenses should request access through their respective Agency PMs or POCs.

  4. Does WebSG Custom support CAM integration?

    Yes. WebSG Custom integrates with CAM via TechPass. Consequently, user account lifecycles and inactive accounts are managed automatically through the inactive account policy.

  5. Does WebSG Custom suspend inactive users?

    Yes. WebSG Custom automatically suspends users if they have not login to the CMS instance for 90 days. This applies to both Staging and Production environments. A reminder message will be sent to the user’s email 7 days before suspension.

  6. What default network restrictions apply to WebSG Custom CMS?

    By default, access to the WebSG Custom CMS instance is locked down and restricted strictly to authorized COMET / SEED devices and WebSG Custom public web servers.

  7. What pre-configured role-based access control (RBAC) roles exist in WebSG Custom?

    WebSG Custom comes pre-configured with standard platform roles including Administrator, Editor, and Publisher. These RBAC roles can be further customized by agency administrators to suit specific governance and operational requirements.

  8. Does WebSG Custom provide access logs for monthly audit reviews?

    Yes. User activity logs are logged in the CMS dashboard under Settings > Activity (/admin/activity).

    To automate monthly audit log reviews, agency web developers can configure an WebSG custom Flow that periodically exports the directus_activity system collection and emails the report to designated agency reviewers.

  9. Can we provide offshore developers access to production repository?

    No. Offshore developers must not be granted direct access to WebSG Custom-provided repositories. If tenant developers require offshore development support, they must configure repository mirroring to an agency-managed repository and grant offshore developers access to that managed repository instead.

  10. What is the Optical_Support@tech.gov.sg account used for?

    The Optical_Support account is used by the platform engineers to support agencies when WebSG Custom support is required. This account cannot be modified.

  11. Can agencies use their own domain for CMS email notifications?

    No. WebSG Custom currently supports only no-reply@optical.gov.sg for CMS notifications.

  12. Can agencies delete the AWS Certificate Manager DNS validation records from WOG ITSM?

    No. Agencies must not delete WebSG Custom-related AWS Certificate Manager (ACM) DNS records from their WOG DNS. Deleting these records will cause DNS validation to fail and may eventually lead to SSL certificate expiry.

    Example ACM DNS validation record:

    • TYPE: CNAME
    • NAME: _1bc93e2579c76***********.agency.gov.sg.
    • VALUE: _648bd840ae1******.j***.acm-validations.aws.

Vendor Procurement

  1. How can my Agency procure external development or maintenance services for our website on WebSG Custom?

    If your agency requires external support for website development, enhancement, or ongoing maintenance, you can engage a web vendor through existing government bulk tenders, such as GVT(T)24014 - Application Development & Support and ICT Professional Services.

     

    Alternatively, agencies may use their own procurement channels (such as an Invitation-To-Tender [ITT] or Direct Contracting) based on their internal procurement guidelines.

 

Subscription & Billing

  1. How is the subscription pricing structured for WebSG Custom?

    Agencies can refer to the official WebSG Custom Pricing Guide for the current subscription rates.

  2. What is included in the standard WebSG Custom subscription package?

    The standard WebSG Custom subscription package includes:

    • Headless CMS Instances: Provisioning for both Staging (STG) and Production (PRD) environments.
    • Frontend Hosting Choice: An option to opt into GovTech-Hosted frontend web application hosting, or choose Agency-Hosted frontend if your agency requires custom configurations.
    • Developer Resources: Access to the WebSG Custom Next.js starter kit, API documentation, and core CMS updates.

    Note: The public web application frontend code, layout design, and frontend performance testing must be managed and maintained by the agency or its appointed vendor.

  3. How are WebSG Custom subscription fees billed to our agency?

    Agencies execute a Universal Service Terms (UST) agreement with GovTech for the WebSG Custom subscription. Subscription fees are invoiced on a quarterly basis, and the subscription carries a minimum commitment period of 12 months.

  4. Does the WebSG Custom subscription cover third-party vendor development and maintenance costs?

    No. Any third-party web vendor costs for custom frontend development, UI/UX design, website enhancements, or ongoing application maintenance must be procured separately by the agency (e.g. via bulk tenders like GVT(T)24014 - Application Development & Support and ICT Professional Services).

  5. Is there a trial version?

    Yes. Request a trial by submitting the form.

Architecture & Data Modelling

  1. Can tenant developers create custom data models if the provided starter kit does not include them?

    Yes. Agencies and tenant developers have full flexibility to define and create custom data models, collections, and fields within WebSG Custom Content Studio to support their specific business requirements.

  2. Can an Agency have multiple sites under a single root agency account, and how is this managed?

    Yes. A single WebSG Custom CMS instance can host and manage multiple websites. However, each individual site requires its own dedicated frontend code repository for hosting, deployment, and configuration.

  3. Does WebSG Custom support multi-channel integration (e.g. one CMS serving a mobile app, digital signage, and a website)?

    Yes. WebSG Custom Content Management System (CMS) operates as a headless CMS and supports multi-channel content delivery via API endpoints. However, the agency is responsible for hosting and managing the frontend applications for additional channels like mobile apps or digital signage.

 

Intranet Restrictions

  1. Does WebSG Custom support intranet websites?

    No. WebSG Custom is designed as a public cloud-hosted CMS and does not support true internal-only (intranet) network deployments.

     

    However, if your agency requires an internet-hosted website to be restricted to specific users or internal networks, IP whitelisting or network access control can be configured upon request by submitting a Service Request (SR) to the WebSG Custom team.

 

Error Pages

  1. Does WebSG Custom support custom-branded maintenance or error pages?

    Currently, the custom maintenance or error page feature is not supported.

    If your business requires this feature, tenant developers should build a custom error/maintenance page, then raise a Service Desk Ticket to the WebSG Custom team for integration.

Content Authoring

  1. Does WebSG Custom support rich text editing, tables, and external link handling?

    Yes. WebSG Custom includes a built-in Rich Text / WYSIWYG Editor that supports consistent formatting, tables, and standard HTML output (headings, bulleted lists, tables).

    External links configured in the CMS automatically append target="_blank" and rel="noopener noreferrer" attributes.

  2. Does WebSG Custom support image resizing, drag-and-drop page builders, or inline iframe embeds natively?

    No. WebSG Custom is a headless CMS and does not function as a drag-and-drop page builder or support native image resizing tools or direct iframe code block embeds.

    These components must be configured, rendered, or built as custom extensions by the agency’s vendor.

  3. Does WebSG Custom include a native drag-and-drop form builder?

    No. WebSG Custom does not provide an out-of-the-box form builder. However, WebSG Custom can store form submission data via API if the vendor builds and integrates the form components on the frontend.

  4. Is there a page lock when an editor is editing a webpage?

    No. WebSG Custom does not have a page lock.

  5. Does WebSG Custom have drag-and-drop capability for menu interface and hierarchy reordering?

    Yes. WebSG Custom supports drag-and-drop ordering of the menu interface.

  6. Does WebSG Custom support Parent/Child hierarchical nested node creation rules?

    Partially. WebSG Custom natively supports parent/child hierarchical data structures. However, custom validation rules or constraints governing nested node creation must be configured by your agency’s web developers.

 

Digital Assets Management (DAM)

  1. Does WebSG Custom support Digital Asset Management (DAM)?

    Yes. WebSG Custom includes an integrated DAM asset library for uploading, tagging, organizing, reusing, and serving media files across your website.

  2. Does WebSG Custom support meta tags for images and media assets?

    Yes. WebSG Custom includes built-in metadata support for media assets (such as title and alt text). Additional custom metadata fields can be created as needed by your agency's web developers.

  3. When a page is deleted, are the associated media assets also deleted?

    No. Deleting a page does not automatically delete its associated media assets. Images and files remain stored in the media library so they can be reused across other pages without broken references.

 

Publishing

  1. Does WebSG Custom support scheduled publishing?

    Yes. WebSG Custom supports scheduled publishing using built-in automation workflows (Flows). The agency’s web developers will need to configure and set up the specific trigger rules and schedule flows to meet your business use case.

  2. Does WebSG Custom support scheduled unpublishing?

    Partially. WebSG Custom supports automatic content unpublishing once a set expiration timestamp is reached via WebSG Custom Flows configured by the vendor.

  3. Does WebSG Custom support workflow approval routing?

    Yes. WebSG Custom supports customizable multi-stage approval workflows via platform Flows. Agency web developers will need to configure the routing logic, user role conditions, and review stages according to your agency’s approval governance.

  4. Can we use SVG files for WebSG Custom logo and media assets?

    No. WebSG Custom does not support the SVG file format for logos.

    While WebSG Custom supports SVG files for media assets, it is best not to use them as the overall security of the website can be weakened. Please read the article “Why SVG is a Hacker’s Canvas” for more information.

  5. How does version control, rollback, and revision tracking work in WebSG Custom?

    WebSG Custom maintains an automated revision history log that records update sessions, timestamps, action descriptors, and usernames.

    Content managers can roll back to a previous content version at any time, with the rollback event recorded in the audit log.

 

Frontend Capabilities

  1. Can content editors create A/B content test variants?

    Yes. WebSG Custom allows editors to store and manage content variants. However, the agency’s vendor must build the frontend logic to fetch, split, and render these variants.

  2. How does WebSG Custom support mobile responsiveness and device previewing?

    Mobile responsiveness is handled at the application layer. Agency vendors are responsible for designing and implementing responsive layouts and preview capabilities within the custom frontend web application.

 

SEO

  1. Does WebSG Custom support Search Engine Optimisation (SEO) features?

    Yes. WebSG Custom provides dedicated CMS metadata fields (e.g., page titles, meta descriptions, canonical links).

    However, technical SEO implementation such as site rendering speed, semantic HTML structure, Core Web Vitals, dynamic robots.txt/sitemap generation, and mobile usability are the responsibility of the agency’s frontend web developer.

Does WebSG Custom provide 24/7 support?
WebSG Custom provides active operational support during standard business hours. For critical incidents occurring outside operating hours, the WebSG Custom team monitors high-priority alerts and will respond on a best-effort basis as soon as possible.

  1. What are the platform availability targets, Recovery Time Objective (RTO), and Recovery Point Objective (RPO) for WebSG Custom?

    WebSG Custom provides platform-level IT resilience with a target system uptime of 99.5%. The platform Recovery Time Objective (RTO) is 8 hours and the Recovery Point Objective (RPO) is 24 hours.

  2. Can Agencies conduct a performance load test on their websites?

    Yes. Agencies can run performance load tests on their hosted Staging websites (e.g. www.stg.agency.gov.sg).

    Agencies are advised to raise a Service Request via the WebSG Custom Service Desk and provide the schedule to the WebSG Custom team. Additionally, the performance load test must be performed using a whitelisted non-SEED and non-GSIB device.

  3. How does WebSG Custom manage a sudden surge in public traffic to my website?

    A Content Delivery Network (CDN) is important for handling sudden surges in website traffic. Agencies and tenant developers are advised to use the Next.js Cache Control Policy according to their business requirements.

  4. How does WebSG Custom handle high availability, contingency, and disaster recovery (DR)?

    WebSG Custom has implemented several measures to ensure high availability and disaster recovery:

    • Data Centre Redundancy & High Availability (Native): WebSG Custom infrastructure is deployed across 3 AWS Availability Zones (AZs) in Singapore. This multi-AZ setup ensures active traffic balancing and automatic failover across three distinct physical data centers, satisfying standard Disaster Recovery (DR) requirements for data center outages.

    Cloud Provider & Regional Redundancy (Not Supported):

    • Multi-Cloud: WebSG Custom operates exclusively on AWS and does not support multi-cloud deployments.
    • Multi-Region: WebSG Custom operates solely within the AWS Singapore Region to comply with local data residency regulations and does not support multi-region deployments.

Vulnerability Assessment and Penetration Testing (VAPT)

VAPT Responsibilities 

(The following information will be displayed on the WebSG Custom Developer Portal)

 

Legend:

  • O = WebSG Custom’s responsibility
  • T = Tenant’s responsibility

 

Component VAPT Type Basic Flex, WebSG Custom-Hosted Flex, Agency-Hosted
Public Web       Web VA O T T
Web PT O T T
Cloud VA O O T
Cloud PT O O T
CMS       Web VA O O O
Web PT O O O
Cloud VA O O O
Cloud PT O O O
Custom Extensions       VAPT N/A T T

 

For VAPT services, agencies may consider using the GovTech Bulk Tender: GVT(T)25001 - Cybersecurity and Audit Services (CSAS) 

 

Security Scans

1. What security scans are conducted automatically during the deployment pipeline?

WebSG Custom’s CI/CD deployment pipeline automatically executes the following security scanning tools:

  • Semgrep: Static Application Security Testing (SAST) to identify code vulnerabilities.
  • Gemnasium: Dependency scanning to detect known vulnerabilities in third-party packages and libraries.
  • Secret Detection: Scans code commits to prevent hardcoded keys, tokens, or credentials from being exposed.

Note: Tenant developers can also leverage GovTech inner-source security repositories to integrate additional or enhanced security testing tools into their pipelines beyond these defaults security scans.

 

Data Governance

1. What is the data security classification for WebSG Custom?

WebSG Custom can host content and data up to Restricted / Sensitive-Normal.

 

2. Is the data encrypted at rest and in transit (in compliance with IM8: DP-2 & DP-3)?

Yes. Data at rest and in transit is fully encrypted in compliance with IM8 DP-2 & DP-3. Additionally, REST API calls to WebSG Custom Content Studio must use the HTTPS protocol.

 

3. How does WebSG Custom ensure tenant data isolation and data control?

WebSG Custom enforces strict logical data segregation at the platform layer to ensure complete tenant isolation. Routing, processing, and application-level data segregation (e.g. custom agency API payloads), as well as data patching due to application-level logic errors, are managed by the agency’s vendor at the application layer.

 

4. What is the backup frequency for WebSG Custom's database?

WebSG Custom performs automated daily full backups of the database, alongside regular Point-in-Time Recovery (PITR) safeguards.

 

5. Can an agency or tenant developer request an ad-hoc database backup or database dump?

Yes. Agencies can submit a Service Request to request a database dump.

URL Redirections

  1. Does WebSG Custom support URL redirection from an old website to a new website?

    Yes. URL redirection or forwarding can be implemented at the application layer. For Next.js frontends, agency developers can configure framework-level routing using redirect() in server components, middleware-based redirects, or route-level rewrite rules depending on the required behavior.

Platform Upgrades

  1. What is the upgrade process for the CMS backend and the frontend (public-web)?

    WebSG Custom follows a semantic versioning model:

    Example: A.1.0

    • A = Major release
    • 1 = Minor version
    • 0 = Patch version

    CMS Backend Upgrade Policy:

    All minor and major versions are automatically applied and managed by the WebSG Custom platform team.

    Frontend (Public-web):

    Tenant developers are fully responsible for managing version upgrades, dependencies, and code releases for their own public web frontend applications.

  2. How are technology refreshes and patch management cycles handled between WebSG Custom and the agency vendor?

    Technology refreshes and patching follow a shared responsibility model:

    • WebSG Custom Scope: WebSG Custom manages continuous tech refreshes and monthly release/patch cycles for core platform infrastructure, base application layers, AWS database clusters, and WebSG Custom-managed frontend hosting environments. High-severity security patches are applied out-of-band as needed.
    • Agency Vendor Scope: The agency’s vendor is responsible for technology refreshes, patch management, and maintenance of custom frontend code, third-party JavaScript libraries/packages, and custom API endpoints.

Content Migration

  1. Can WebSG Custom assist with migrating our existing website to the WebSG Custom platform?

    No. WebSG Custom is a self-serve platform and does not provide professional content or code migration services. Agencies requiring end-to-end migration support can procure external vendor services through government bulk tenders, such as GVT(T)24014 - Application Development & Support and ICT Professional Services.

  2. Does WebSG Custom support migrating custom collection rows between Non-Production and Production environments?

    Manual / API-based. WebSG Custom supports syncing custom collections between Staging and Production. However, automated schema or data-row sync synchronisation is not supported out of the box. Tenant developers can utilize the Directus Items API to script and automate custom data migration mechanisms across environments.

CI/CD

  1. What is the process to trigger code deployment and UAT in the Staging environment?

    The UAT schedule is agreed upoin first. The developer then creates a merge request in their own repository’s main branch and the designated Tech Lead reviews and merges it. After that, the GitLab mirror syncs the code to the WebSG Custom GitLab main branch, which triggers the deployment pipeline. The pipeline runs the build, packaging, and security tests, then generates reports, pushes the image to ECR, and deploys to Staging.

    Any security findings must be fixed by the development team, or a security risk acceptance must be raised by the tenant developer. While these issues are being addressed, the agency performs UAT. Once Staging UAT is complete, the agency gives approval for Production deployment. After approval, the Production resources are deployed.

Extensions

  1. Do we use separate code repositories for individual extensions?

    Yes. Each extension requires its own dedicated code repository within your agency's project group.

    Example Repository Structure:

    Agency
    ├── WebSG Custom Public Web
    └── Extensions
        ├── Extension A
        └── Extension B

  1. Does the entire site cache get invalidated when an agency updates content and publishes the page?

    Currently, the cache is invalidated when the cache TTL expires. Additionally, WebSG Custom provides self-service CDN cache invalidation.

    Please raise a Service Desk ticket to the WebSG Custom team to enable the self-service capability.

  2. Does WebSG Custom have an email campaign or newsletter feature?

    No. WebSG Custom does not currently offer native email marketing or campaign management features. Agencies needing mass email capabilities should integrate with dedicated third-party services (e.g. Postman.gov.sg).

  3. How can we send internal transactional emails from WebSG Custom Content Studio?

    You can use the native email operation feature in WebSG Custom Flows.

    Note: Emails are currently dispatched from the default system address no-reply@staging.optical.gov.sg, which cannot be customized to an agency domain.

  4. What is the maximum file size supported by the WebSG Custom File Library?

    By default, the WebSG Custom File Library supports individual file uploads up to 100 MB. If your agency requires a lower maximum file upload limit for security or governance reasons, you can submit a Service Request (SR) to the WebSG Custom support team.

  5. What are the allowed file types by the WebSG Custom Media Library?

    The allowed list of media file types is shown in the table below:

    MIME Type File Extensions
    image/jpeg .jpg, .jpeg, .jfif
    image/png .png
    image/gif .gif
    image/webp .webp
    image/avif .avif
    image/bmp .bmp
    image/tiff .tif, .tiff
    image/heic .heic
    image/x-icon .ico
    application/pdf .pdf
    text/plain .txt
    text/csv .csv
    application/json .json
    application/xml .xml, .xslt
    text/calendar .ics
    application/rtf .rtf
    application/msword .doc
    application/vnd.openxmlformats-officedocument.wordprocessingml.document .docx, .dotx
    application/vnd.ms-excel .xls
    application/vnd.openxmlformats-officedocument.spreadsheetml.sheet .xlsx
    application/vnd.ms-powerpoint .ppt
    application/vnd.openxmlformats-officedocument.presentationml.presentation .pptx, .ppsx
    audio/mpeg .mp3
    audio/wav .wav
    audio/ogg .ogg
    video/mp4 .mp4
    video/webm .webm
    video/quicktime .mov
    video/ogg .ogv
    font/ttf .ttf
    font/otf .otf
    font/woff .woff
    font/woff2 .woff2
    application/vnd.ms-fontobject .eot
  6. Is there a database storage limit for WebSG Custom subscriptions?

    No. Currently, WebSG Custom subscriptions do not impose a strict data storage cap on the database.

  7. What is the data transfer limit for WebSG Custom subscriptions?

    Currently, there is no data transfer limit for any of the WebSG Custom hosting subscriptions.

  8. Does WebSG Custom offer native web analytics and reporting tools?

    No. WebSG Custom does not include native web analytics or reporting dashboards. However, agency vendors can integrate third-party web analytics tools (e.g., WOGAA, Google Analytics 4, or Adobe Analytics) on the custom frontend.

  9. How can agencies monitor website uptime and receive alert notifications?

    WebSG Custom maintains internal uptime monitoring for core CMS availability. For custom uptime alerts and external site monitoring, agencies can configure StackOps log alerts or register their website on WOGAA to receive automated SMS and email alerts during service disruptions.

  10. How can we view the CMS and web application logs in WebSG Custom?

    WebSG Custom uses StackOps for logging. Please raise a Service Desk Ticket to the WebSG Custom team.

    Additionally, please refer to the StackOps documentation to familiarise yourself with the dashboard.

Last updated 11 Sep 2026

Was this article useful?

A Headless Content Management System that supports Custom Web Capabilities.