Drafts & publishing

The Pages collection has Payload's built-in drafts enabled (versions.drafts) - not a custom versioning system.

Why this needed explicit access control

Payload's draft parameter on find/findByID controls which version is returned when you ask for it - it does not filter out documents whose _status is "draft" from a normal query. The public render route explicitly filters where: { _status: { equals: "published" } }, and the Pages collection's access.read enforces the same rule for anyone using the REST/GraphQL API directly (the Local API used by this app's own routes bypasses access control by default, so both guards matter).