Access and provisioning requests
Requests, approvals, temporary grants and automatic revocation, with a decision trail.
For IT and security leaders
Departments will build their own tools; the question is where. ToolJet gives them an AI-assisted builder that lives inside your identity, permissions and audit controls, on infrastructure you choose. Shadow spreadsheets become governed apps.
| Request | Requester | Approver | Status |
|---|---|---|---|
| Read access · billing DB | A. Chen | Data platform | Approved |
| Admin · CRM sandbox | R. Patel | IT ops | In review |
| Prod deploy rights | J. Moreau | Platform eng | Denied |
| Temporary VPN · vendor | K. Adeyemi | Security | Approved |
Expire any temporary access after 7 days and post the revocation to #security-audit
Scheduled workflow and Slack query added · awaiting your review
No engineering ticket needed
Type what you want in plain language. ToolJet generates the pages, queries and logic as a working app. Connect your data, set who can see what, and review the generated logic before publishing. Edit the app on the canvas afterwards.
Connects to the systems IT already runs
Have developers? They can build the same apps fromthrough the ToolJet plugin
Requests, approvals, temporary grants and automatic revocation, with a decision trail.
Hardware, software and licence registers with owners, renewals and audit exports.
Checklists that read from your directory and write to ticketing, so no account is left behind.
Lightweight change and incident logs where a full ITSM suite is overkill.
Finance, HR and operations build their own tools inside your controls instead of in spreadsheets and SaaS trials.
Exportable audit logs and permission reports that answer auditor questions without a scramble.
ToolJet Cloud, your VPC, on-premise or fully air-gapped. Docker, Kubernetes, Helm and OpenShift are supported.
SAML, OIDC or LDAP. Map directory groups to ToolJet roles and turn on SCIM so joiners and leavers are handled for you.
Platform admins configure data sources with scoped credentials and define role permissions. Builders work within them.
Let departments describe the tools they need. Review requests where the data is sensitive; the rest ships under the rules you set.
In production
Security review, answered
SOC 2 Type II, ISO 27001 and GDPR, with the details in the trust centre. TLS protects data in transit, and AES-256-GCM encrypts data source credentials.
SAML, OIDC and LDAP with group-to-role mapping; SCIM provisioning and deprovisioning.
Workspace, app, page, component and query-level access; row-level security for scoped data.
Platform events with actor, resource and timestamp; configurable retention; export to your SIEM.
Self-hosted Enterprise offers BYOK and private AI deployment options. Use a local model endpoint when inference must stay within your network.
Security and governance features vary by plan. Workflows and Agent Builder are available on Self-hosted only; BYOK is a Self-hosted Enterprise add-on. Compare plan availability.
See the full control model Visit the trust centre Deployment options
Two ways to get there
Self-serve
Start free. Describe the tool, refine it on the canvas, and ship it under your own access rules. Start with one app, then test it with your team before rolling it out.
Start freeProfessional services
When the timeline is fixed or the process is tangled, our engineers build alongside you: scoped delivery, production-ready apps, and knowledge transfer so your team owns the result.
Talk about a projectWherever you deploy ToolJet. Self-host in your VPC or on-premises, with an Enterprise add-on for air-gapped deployment. External AI providers and connected services can receive data according to your configuration. On ToolJet Cloud, data source credentials are encrypted and queries run server-side; a data processing agreement and regional options are available.
Default managed AI routes requests through ToolJet AI Cloud to model providers. Self-hosted Enterprise supports BYOK and private AI deployment; keeping inference internal requires a local model endpoint. Review the data flow for the setup you choose.
Roles define who can build, who can publish and which data sources and queries each group can use. Row-level security scopes records. Builders inherit those limits; they cannot grant themselves more.
Yes. Platform audit logs record events with actor, resource and timestamp, with configurable retention and SIEM export. Business-level approval records live in the apps you build, so auditors get both.
SOC 2 Type II, ISO 27001 and GDPR, regular penetration testing, TLS in transit and AES-256-GCM encryption for data source credentials. Reports and the security policy are in the trust centre.
Walk through deployment, identity and audit on a call with an engineer. Bring your questionnaire.
Page updated