Skip to content

For IT and security leaders

Internal tools that pass review before they are built

Departments will build their own tools; the question is where. ToolJet gives them an AI-assisted builder that lives inside your identity, permissions and audit controls, on infrastructure you choose. Shadow spreadsheets become governed apps.

  • Replace shadow IT
  • Self-host or air-gap
  • One identity for every app
Example IT leaders app · illustrative data
Access requestsPending · all systemsSSOAudit onProduction
Open requests183 over SLA
Approved this week92median 26 min
Auto-revoked14expired temporary access
RequestRequesterApproverStatus
Read access · billing DBA. ChenData platformApproved
Admin · CRM sandboxR. PatelIT opsIn review
Prod deploy rightsJ. MoreauPlatform engDenied
Temporary VPN · vendorK. AdeyemiSecurityApproved

Expire any temporary access after 7 days and post the revocation to #security-audit

Scheduled workflow and Slack query added · awaiting your review

40,000+stars on the open-source core
AICPA SOCISO 27001
SOC 2 Type IIISO 27001 and GDPR · Visit the trust centre
Your infrastructureCloud, VPC, on-premise or air-gapped
100+ connectorsplus any REST or gRPC endpoint

No engineering ticket needed

Describe the tool you need. ToolJet builds it.

Type what you want in plain language. ToolJet generates the pages, queries and logic as a working app. Connect your data, set who can see what, and review the generated logic before publishing. Edit the app on the canvas afterwards.

  • Working app, not a mockup
  • Review access rules before publishing
  • Free to start, per-builder pricing
Enter to build · Shift+Enter for a new line

Connects to the systems IT already runs

  • Microsoft 365
  • SharePoint
  • Jira
  • Slack
  • PostgreSQL
  • REST API
  • Zendesk
  • Google Sheets
Browse all integrations

Have developers? They can build the same apps fromClaude CodeCodexCursorGitHub CopilotGrok Buildthrough the ToolJet plugin

What IT teams build, and what they let others build

Access and provisioning requests

Requests, approvals, temporary grants and automatic revocation, with a decision trail.

Asset and licence management

Hardware, software and licence registers with owners, renewals and audit exports.

Onboarding and offboarding

Checklists that read from your directory and write to ticketing, so no account is left behind.

Incident and change records

Lightweight change and incident logs where a full ITSM suite is overkill.

Governed apps for other departments

Finance, HR and operations build their own tools inside your controls instead of in spreadsheets and SaaS trials.

Compliance evidence

Exportable audit logs and permission reports that answer auditor questions without a scramble.

How a rollout usually goes

  1. 01

    Choose the boundary

    ToolJet Cloud, your VPC, on-premise or fully air-gapped. Docker, Kubernetes, Helm and OpenShift are supported.

  2. 02

    Connect identity

    SAML, OIDC or LDAP. Map directory groups to ToolJet roles and turn on SCIM so joiners and leavers are handled for you.

  3. 03

    Set the guardrails once

    Platform admins configure data sources with scoped credentials and define role permissions. Builders work within them.

  4. 04

    Open it up

    Let departments describe the tools they need. Review requests where the data is sensitive; the rest ships under the rules you set.

In production

Teams already running on ToolJet

Security review, answered

The controls your questionnaire asks about

SOC 2 Type II, ISO 27001 and GDPR, with the details in the trust centre. TLS protects data in transit, and AES-256-GCM encrypts data source credentials.

SSO and SCIM

SAML, OIDC and LDAP with group-to-role mapping; SCIM provisioning and deprovisioning.

Permissions to the query

Workspace, app, page, component and query-level access; row-level security for scoped data.

Audit logs and SIEM export

Platform events with actor, resource and timestamp; configurable retention; export to your SIEM.

AI inside your boundary

Self-hosted Enterprise offers BYOK and private AI deployment options. Use a local model endpoint when inference must stay within your network.

Security and governance features vary by plan. Workflows and Agent Builder are available on Self-hosted only; BYOK is a Self-hosted Enterprise add-on. Compare plan availability.

Two ways to get there

Build it yourself, or bring our engineers in

Self-serve

Your team, your pace

Start free. Describe the tool, refine it on the canvas, and ship it under your own access rules. Start with one app, then test it with your team before rolling it out.

Start free

Professional services

Forward-deployed engineers, embedded with your team

When the timeline is fixed or the process is tangled, our engineers build alongside you: scoped delivery, production-ready apps, and knowledge transfer so your team owns the result.

Talk about a project

Questions IT leaders ask before they start

Where does our data live?

Wherever you deploy ToolJet. Self-host in your VPC or on-premises, with an Enterprise add-on for air-gapped deployment. External AI providers and connected services can receive data according to your configuration. On ToolJet Cloud, data source credentials are encrypted and queries run server-side; a data processing agreement and regional options are available.

Does the AI send our data to a model provider?

Default managed AI routes requests through ToolJet AI Cloud to model providers. Self-hosted Enterprise supports BYOK and private AI deployment; keeping inference internal requires a local model endpoint. Review the data flow for the setup you choose.

How do we control what non-technical builders can do?

Roles define who can build, who can publish and which data sources and queries each group can use. Row-level security scopes records. Builders inherit those limits; they cannot grant themselves more.

Is there an audit trail for compliance?

Yes. Platform audit logs record events with actor, resource and timestamp, with configurable retention and SIEM export. Business-level approval records live in the apps you build, so auditors get both.

How is ToolJet itself secured?

SOC 2 Type II, ISO 27001 and GDPR, regular penetration testing, TLS in transit and AES-256-GCM encryption for data source credentials. Reports and the security policy are in the trust centre.

Give the business a builder you can stand behind

Walk through deployment, identity and audit on a call with an engineer. Bring your questionnaire.

Page updated