SSO and visibility for apps
Control who can access each app in your workspace — public, workspace-only, or SSO-gated for your end users.
App-level access control
Beyond workspace SSO (which controls who can build in bldrAgent), you can also control who can use each app you publish.
This is configured in App Settings → Access.
App visibility options
| Option | Who can access the app |
|---|---|
| Public | Anyone with the URL |
| Logged-in users | Any user who creates an account in your app |
| Workspace SSO | Only users authenticated via your workspace's SSO provider |
| Invite only | Only specific email addresses you invite |
Using workspace SSO to gate app access
This is the most common enterprise use case. Your employees sign in with their corporate identity (Google Workspace, Okta, etc.) to access internal tools built on bldrAgent.
Setup:
- Configure workspace SSO first
- Open the internal app in the editor
- App Settings → Access → Visibility → Workspace SSO
- Publish the app
Now when employees visit the app URL, they're redirected to your company's identity provider login, and automatically granted access.
Role mapping from SSO
If your IdP sends a role attribute in the SAML assertion, bldrAgent can map it to app-level roles:
Example: Users in the admin group in Okta automatically get the Admin role in the app.
Configure this in App Settings → Access → Role mapping.
Public apps with optional login
For customer-facing apps, you can keep the app publicly accessible while offering optional login:
"Add optional login to the app. Anonymous users can browse and view content. Logged-in users can save items, leave reviews, and access their purchase history."
This gives users a frictionless first experience while enabling personalisation for authenticated users.
App access audit log
Enterprise workspaces can view a log of all access events for each app:
- Login / logout events
- Failed login attempts
- Access from new devices or locations
App Settings → Access → Audit log
