App Access

Your subscription packs decide which apps your company has. The app access filter decides which of those apps a specific user sees — useful when someone only needs one or two apps out of a whole pack.

Two modes

ModeBehaviour
All (default)The user sees every app their tenant’s packs unlock
AllowlistThe user only sees the apps you pick

The filter is always the intersection with your packs: it can hide licensed apps, but it can never add an app your company hasn’t purchased. Example: your company has the Business Pack (CRM, Sales, POS…), but a new hire only needs CRM — set their filter to allowlist with just CRM, and the other apps disappear from their app switcher.

Configure a user’s app access

Open the user

Go to Settings → Users (/settings/users) and open the user’s detail page.

Edit the filter

In the App Access section, switch the mode to Allowlist and tick the apps this user should see. Leave the mode on All to give them everything the packs include.

Save

The user’s app switcher and navigation update accordingly.

A UX restriction, not a security boundary

⚠️

The app filter simplifies the interface — it hides apps from the user’s navigation. It is not what protects your data: permissions and data scope govern what a user can actually read or change, and those are enforced on the server regardless of the filter. Use the filter to declutter, use roles to secure.

When to use it

Most users should stay on All. Reach for an allowlist when:

  • Onboarding a specialist who only needs one or two apps from a pack.
  • Your company bought a pack for its platform features but wants a cleaner interface for certain groups of users.