Admin

Policies

The rules every app in the workspace follows.

Open Admin → Policies, change what you need, and choose Save changes. The rules apply to every app in the workspace, from each app's next deploy. Turning off public links applies at once.

Sign-in

PolicyWhen onDefault
Company login on every appEvery app requires a company Google account. No app can turn this off.On
Allow guests from other domainsApps can be shared with people outside the company by email, such as agencies and contractors. When off, outside emails are refused (guests_not_allowed).Off

Publishing

PolicyWhen onDefault
Security scan must passApps with blocking issues, such as secrets in code or unknown domains, cannot be listed for everyone at the company.On
Allow public linksApps can be set to Anyone with the link. Turning this off moves every such app back to Only people added at once.Off

Company directory

Each of these changes new requests only.

PolicyWhen onWhen offDefault
Directory submission approvalAn admin approves an app before it appears in the directory.It is listed at once with a "New" badge.On
Suggested changes approvalAfter an owner accepts changes from a copy, an admin approves them before they go into the original.Accepted changes go in at once.On
Unlist approvalAn admin approves before an owner removes their app from the directory.The owner unlists at once.On

Requests waiting on these show under Admin → Directory. See Directory queue.

Allowed external domains

The outside websites apps may send data to. See Allowed domains.

Data connectors

Whether apps may use connectors such as HubSpot, set to Off, Read only or Read and write. Each viewer connects their own account, so an app acts with that person's own permissions.

Members can see a read-only summary of the policies that affect them, such as whether public links are allowed, in the Share dialog.