Admin
Policies
The rules every app in the workspace follows.
Open Admin → Policies, change what you need, and choose Save changes. The rules apply to every app in the workspace, from each app's next deploy. Turning off public links applies at once.
Sign-in
| Policy | When on | Default |
|---|---|---|
| Company login on every app | Every app requires a company Google account. No app can turn this off. | On |
| Allow guests from other domains | Apps can be shared with people outside the company by email, such as agencies and contractors. When off, outside emails are refused (guests_not_allowed). | Off |
Publishing
| Policy | When on | Default |
|---|---|---|
| Security scan must pass | Apps with blocking issues, such as secrets in code or unknown domains, cannot be listed for everyone at the company. | On |
| Allow public links | Apps can be set to Anyone with the link. Turning this off moves every such app back to Only people added at once. | Off |
Company directory
Each of these changes new requests only.
| Policy | When on | When off | Default |
|---|---|---|---|
| Directory submission approval | An admin approves an app before it appears in the directory. | It is listed at once with a "New" badge. | On |
| Suggested changes approval | After an owner accepts changes from a copy, an admin approves them before they go into the original. | Accepted changes go in at once. | On |
| Unlist approval | An admin approves before an owner removes their app from the directory. | The owner unlists at once. | On |
Requests waiting on these show under Admin → Directory. See Directory queue.
Allowed external domains
The outside websites apps may send data to. See Allowed domains.
Data connectors
Whether apps may use connectors such as HubSpot, set to Off, Read only or Read and write. Each viewer connects their own account, so an app acts with that person's own permissions.
Members can see a read-only summary of the policies that affect them, such as whether public links are allowed, in the Share dialog.