Security

Publish to the company

List an app in the company directory so everyone at the company can open it.

In a company workspace, "everyone at the company" means the company directory. Listing an app there does two things together:

  1. people can find it in the directory
  2. general access becomes Everyone at the company, as Viewers

Editing stays with the app's Editors and Owner. Personal workspaces have no directory.

Submit an app

Editors and the Owner can submit an app. Do it in one of these ways:

  • On the app's page, choose Submit to directory on the Directory card.
  • On the app's security review, choose Publish to company.
  • Ask your AI tool: "Share the lead tracker with the whole company." It uses submit_to_directory, or share_app with "company".

The form asks for the name, a one-line description, the team it is listed under, the README and an optional icon or screenshot. The team is one of the workspace's teams (its groups), or any name you type.

Before you can submit

  • The app has a live version.
  • The security scan of that version has finished, AI review included.
  • No blocking issue is open on it. Warnings are fine.

Admin approval

Admins choose under Policies → Company directory whether a new listing needs their approval. It does unless an admin turned Directory submission approval off.

  • On: admins are emailed and the app waits in their directory queue. They can Approve, Reject or Request changes. Until they decide, you can Withdraw the request.
  • Off: the app is listed at once with a New badge, and admins are told.

After it is listed

You keep deploying as usual. Each new version, and each rollback, is compared with the version that was approved:

  • Nothing risky: the directory simply shows the new version.
  • Something risky, such as a new outside domain, a new secret or new scan findings: the update shows as pending in the admins' directory queue until one approves it.
  • A blocking issue: the app is hidden from the directory until the issue is fixed or you roll back.

Unlist

The Owner can take the app out of the directory: choose Unlist on the app's Directory card, or ask your AI tool (unlist_from_directory). Give a short reason.

  • When Unlist approval is on (the default), an admin approves first. The app stays listed until they decide.
  • An admin can unlist any app at once. The Owner is told why.

After it is unlisted, general access goes back to Only people added. People added by name keep their access.