Skip to main content
Organization Admin permissions are required to access and modify app policy settings.
The Settings > Apps tab controls whether your organization can use Apps, which external hosts those apps may load resources from, and which external sites they may embed as iframes.

Enable apps

Controls whether your organization can use Apps, which let you build custom data experiences beyond traditional dashboards. To restrict app creation to specific users or groups rather than turning apps off entirely, use the granular permission on a custom role.

External source policy

Apps run in a sandboxed iframe whose Content Security Policy blocks outbound network requests by default. The External source policy sets the organization-wide ceiling on which external hosts that policy will open up — for images, scripts, stylesheets, fonts, and network connections. It doesn’t control embedded iframes; the Embedded frame policy does. This is separate from, and takes precedence over, the Safe domains setting an app editor configures on an individual app.

Policy options

Omni defaults is the policy for an organization that hasn’t chosen one.
Under Custom, your list replaces Omni’s default hosts. If your apps rely on a default host — a charting library from cdn.jsdelivr.net, or fonts.googleapis.com — you have to list it yourself or those resources stop loading.This includes map libraries. If an app shows a map, list the CDN that the app loads its map library from: unpkg.com, cdn.jsdelivr.net, or cdnjs.cloudflare.com.
To block external loading entirely, choose Custom and leave the host list empty. There’s no separate off switch: an empty custom list means an app loads nothing from any external host.

Setting a custom host list

  1. Go to Settings > Apps.
  2. Under External source policy, set Source policy to Custom.
  3. Enter your hosts in the Custom hosts field. Add one host per line, or separate them with commas or spaces:
  4. Click Save source policy.
A custom list accepts up to 25 hosts and uses the same formats as an app’s Safe domains. A *. wildcard matches subdomains but not the domain itself, so *.example.com covers cdn.example.com but not example.com.

Embedded frame policy

The Embedded frame policy sets the organization-wide ceiling on which external sites apps can embed as iframes. It’s separate from the External source policy, and takes precedence over the Embedded frames setting an app editor configures on an individual app.
An embedded site can receive an app’s query data, and an app can also navigate to any host it’s allowed to embed. Only allow hosts you trust.

Policy options

No embedded frames is the policy for an organization that hasn’t chosen one. Unlike the External source policy, there are no default hosts: apps can’t embed any external site until an admin changes this policy. To block embedded frames with Custom, leave the host list empty.

Setting a custom frame host list

  1. Go to Settings > Apps.
  2. Under Embedded frame policy, set Frame policy to Custom.
  3. Enter your hosts in the Custom frame hosts field. Add one host per line, or separate them with commas or spaces:
  4. Optional: Turn on Allow these hosts by default to let every app embed the listed hosts without configuring its own Embedded frames setting. An app editor can still limit an app to fewer hosts. When this setting is off, which is the default, an app can embed a listed host only after an app editor adds it to the app’s Embedded frames.
  5. Click Save frame policy.
Hosts use the same formats as an app’s Safe domains.
Allowing a host only removes Omni’s block. A site still won’t render if it doesn’t allow framing, requires a login, or needs a page origin to load.

Map providers

Controls whether apps may render maps from the approved keyless providers (OpenStreetMap, Carto). When Allow map providers is enabled, individual apps can enable or disable map providers in their settings. When disabled, apps cannot load map tiles at all, regardless of its settings.

Printing and dialogs

Controls whether apps can use the browser’s print function and native dialogs (alert, confirm, prompt) inside their iframe, via the allow-modals sandbox permission. When Allow printing and dialogs is enabled, individual apps can enable or disable printing and dialogs in their own settings. When disabled, apps cannot call window.print() or show dialogs at all, regardless of its settings.

Verify changes

Controls whether Omni runs its post-edit verification check — the Changes verified · N tests passed report shown after a chat edit to a draft app. Enabled by default. When enabled, the check runs after every chat edit to a draft app. When disabled, the check is skipped for every app in the organization.

Next steps