Admin controls for app connections

Enterprise admins need to control how app connections are created and shared across their organization. Without controls, sensitive credentials can leave with departing employees, members can connect personal accounts instead of business accounts, and unauthorized access to critical systems becomes harder to prevent.

Zapier provides several options for controlling app connections, each suited to different situations. By the end of this article, you will understand when to use managed connections, managed apps, allowed domains, and app access policies.

Available on plans:

Free

Professional

Team

Enterprise

Comparing your options

Managed connections

  • What it controls: Share organization-owned connections that admins manage
  • Effect on members: Can still create their own personal connections
  • Auth types: All
  • Best for: Mixed-use apps like Slack or Salesforce where you want both company and personal connections

Use managed connections when you want to provide company-owned credentials without restricting members from creating their own connections.

Managed apps

  • What it controls: Who can create connections for an app
  • Effect on members: Cannot create connections for this app
  • Auth types: All
  • Best for: API key apps like OpenAI, sensitive credentials, offboarding protection

Use managed apps when you need full admin control and want to prevent members from creating any connections. This is the only option for API key-based apps where allowed domains do not apply.

Allowed domains

  • What it controls: Which OAuth domains can be used
  • Effect on members: Can create connections, but only to approved domains
  • Auth types: OAuth only
  • Best for: OAuth apps where members might connect personal instead of business accounts

Use allowed domains when you want members to create their own connections but need to ensure they authenticate with business accounts.

App access policies

  • What it controls: Which apps can be used at all
  • Effect on members: Cannot use blocked apps
  • Auth types: N/A
  • Best for: Blocking unauthorized apps entirely

Use app access policies when you need to control which apps your team can use, not just who manages the credentials.

Combining approaches

These options work together. For example, you might use managed connections for Salesforce, mark OpenAI as a managed app, set allowed domains for Gmail, and block social media apps with access policies.

Next steps

Was this article helpful?
0 out of 0 found this helpful