Skip to content

article

Control per-app access for members

Grant or revoke access to individual apps for each member, understand why admins and owners always have full access, and give people exactly the apps they need.

Two layers decide what a member can open

Whether a teammate can open a given app depends on two gates, both on the same /team (Team & Access) screen and the organization's plan:

  1. Role. Owners and admins have full access to every app the organization is entitled to — automatically. There's nothing to toggle for them.
  2. Per-app grant (members only). A member's access is granular: you choose exactly which apps that member can open, app by app. Anything you don't grant stays closed to them.

This is separate from entitlement — whether the organization's plan includes an app at all. Per-app access decides which members get the apps the organization already has. See Understand app entitlements and locked apps for how the plan-level gate works alongside this.

Steps: grant or revoke apps for a member

  1. Open /team.
  2. Find the member you want to configure. If their role is member, you'll see an access grid of app checkboxes on their card.
  3. Check an app to grant access; uncheck it to revoke. Each checkbox corresponds to one workspace app.
  4. Select Save access (the save icon) on that member's card to apply your changes.
  5. The member now sees and can open exactly the apps you checked — nothing more.

Why owners and admins show every app checked

When you look at an owner or admin on /team, their app grid shows every app checked and locked (you can't uncheck them). That's by design: full-access roles bypass the per-app grant entirely. If you need to limit someone to specific apps, they must be a member, not an admin or owner. Promoting a member to admin will grant them full app access and remove the granular control.

Steps: limit an over-permissioned person

  1. On /team, check the person's role. If they're an admin or owner and you want them restricted, they can't be — full-access roles see everything.
  2. Change their role to member using the role dropdown, then Save access.
  3. Their app grid becomes editable. Check only the apps they should have.
  4. Save access again to lock in the granular set.

Realistic example

Northwind Studio has StretchDesign, StretchDrive, StretchProjects, StretchCRM, and StretchBooks on its plan. The admin, Kaya, onboards two members:

  • Ravi (designer) — Kaya grants StretchDesign, StretchDrive, and StretchProjects, and leaves CRM and Books unchecked. Ravi never sees client sales or finance data.
  • Nia (account manager) — Kaya grants StretchCRM, StretchProjects, and StretchBooks, leaving Design unchecked.

Each opens only their granted apps. When a new intern joins who needs to see everything temporarily, Kaya could promote them to admin — but instead keeps them a member and simply checks all the apps, so she can pare it back later without changing their role.

Tips

  • Grant the minimum that lets someone do their job. It's easy to add an app later; tight defaults protect sensitive data (finance, CRM, vault-type apps).
  • Use member + granular grants for anyone who shouldn't see everything. Reserve admin/owner for people who genuinely need full access.
  • Re-check grants when roles change. Promoting to admin grants everything; demoting back to member restores granular control but starts from whatever was last saved — review the grid after any role change.
  • Save on the right card. Changes apply per member when you select that member's Save access button.

Troubleshooting

  • A member can't open an app you granted. Confirm the grant is saved, and confirm the organization's plan actually includes that app — a member can only be granted apps the org is entitled to. If the app is locked at the plan level, no member grant will open it (see Understand app entitlements and locked apps).
  • You can't uncheck apps for someone. They're an owner or admin (full access). Change them to member first to get granular controls.
  • A member sees an app you didn't grant. They may hold that access through a different role, or the change wasn't saved. Re-open /team, verify the role and grid, and Save access.

FAQ

Can a member grant themselves an app? No. Only owners and admins edit the access grid. Members can't change their own grants.

Does removing an app grant delete the member's work? No. Revoking access only closes the door to that app for that person; data the organization owns remains.

What's the difference between this and entitlements? Entitlement is org-level (does the plan include the app?). Per-app access is member-level (does this person get an app the org already has?). Both must be true for a member to open an app.

Was this helpful?

Help us improve this article

Use these controls to share whether this answer solved the issue. Feedback helps prioritize updates to StretchSuite Support.