Configure app access settings for your Enterprise account

You can use app access settings to control which apps members of your Enterprise account can use in Zap workflows and Agents. Enterprise accounts use either restricted apps (an open policy) or allowed apps (a closed policy). New Enterprise accounts use allowed apps by default. By the end of this tutorial, you'll have configured your app access settings to restrict or allow apps for your account members.

Available on plans:

Free

Professional

Team

Enterprise

Before you begin

  • You must be an admin, super admin, or owner of your account to enable this feature.
  • Your account must have one or more verified domains.
  • Familiarity with app access policies is helpful to understand the difference between restricted and allowed apps.

Select your app access setting

  1. In the left sidebar on the Zapier home page, click Admin Center.
  2. In the left sidebar under the Governance section, select App permissions.
    • Enterprise accounts created on or after October 5, 2026 will display the Allowed apps page. Accounts created before October 5, 2026 will display the setting that are already in use.
    • You cannot switch between settings in the Admin Center. Until October 12, 2026, you can request that Zapier Support switch it for you. After that date, switching will be temporarily unavailable.
Restrict an app Allow an app

Restrict apps

When you restrict an app, no one in your account can use that app. Members can still use any app that is not on your restricted list.

Add a restricted app

  1. In the left sidebar on the Zapier home page, click Admin Center.
  2. In the left sidebar under the Governance section, select App permissions.
  3. Click Add app. You'll be redirected to the Add restricted app page.
  4. In the Search for an app field, search for and select the app you want to restrict.
    • You'll see a warning notification if any members are currently using the app.
    • You can review the app connections and any associated Zap workflows on the Apps page.
  5. Click Add restricted app.

Remove a restricted app

  1. On the Restricted apps page, select the app. You'll be redirected to the restriction page for the app.
  2. In the top right, click Remove APP restriction. A dialog box will appear.
  3. Click Remove to confirm.

(Optional) Add member or team exceptions

You can create exceptions to your restricted list so specific members or teams are permitted to use the app.

  1. On the Restricted apps page, select the app. You'll be redirected to the restriction page for that app.
  2. In the Allow app for specific members or teams field, search for and select a member or team in your account.

(Optional) Remove member or team exceptions

  1. On the Restricted apps page, select the app. You'll be redirected to the restriction page for that app.
  2. In the Members/teams with access section, click Remove next to the exempted member or team.
  3. The button will convert to "Are you sure?".
  4. Click Are you sure? to confirm.
Example

If you add Quickbooks to your restricted apps list, you can add an exception for your accounting team. This will give your accounting team access to Quickbooks, while the rest of your account will still be restricted from using the app.

Limitations

  • You can only enable either restricted apps or allowed apps settings. You cannot enable both.
  • You cannot switch settings in the Admin Center. Learn more about switching policies.
  • Members of your account will still be able to connect their app accounts and use them to set up triggers and actions (including loading or creating test records), but they will not be able to publish and run the Zap. Agents that use a restricted app may also be impacted.
  • You can only add an exception for one member or team at a time.
  • By default, these settings are account-wide. Account admins, super admins, and owners will be affected by these limits unless you add exceptions.
  • API by Zapier is not governed by app access controls. Users with API keys can access restricted APIs through API by Zapier. To control API by Zapier usage, mark it as a managed app.

Plan limitation

  • If you downgrade your Enterprise account, you will lose access to this feature.
Note

Switching policies can disrupt your workflows. If you ask Zapier Support to switch your account's policy, Zap steps using affected apps may be held, Agents may not run as expected, and members may be unable to publish Zap workflows until the app is permitted under the new policy. Before requesting a switch, identify affected Zap workflows and Agents, prepare your new app list, and communicate changes to your team. Learn more about what happens when you switch policies.

Next steps

You've configured app access settings for your Enterprise account.

Was this article helpful?
1 out of 1 found this helpful