Organization Admin permissions are required to access and modify app policy settings.
Enable apps
Controls whether your organization can use Apps, which let you build custom data experiences beyond traditional dashboards. To restrict app creation to specific users or groups rather than turning apps off entirely, use the granular permission on a custom role.External source policy
Apps run in a sandboxed iframe whose Content Security Policy blocks outbound network requests by default. The External source policy sets the organization-wide ceiling on which external hosts that policy will open up — for images, scripts, stylesheets, fonts, and network connections. This is separate from, and takes precedence over, the Safe domains setting an app editor configures on an individual app.Policy options
Omni defaults is the policy for an organization that hasn’t chosen one.
To block external loading entirely, choose Custom and leave the host list empty. There’s no separate off switch: an empty custom list means an app loads nothing from any external host.
Setting a custom host list
- Go to Settings > Apps.
- Under External source policy, set Source policy to Custom.
-
Enter your hosts in the Custom hosts field. Add one host per line, or separate them with commas or spaces:
- Click Save source policy.
*. wildcard matches subdomains but not the domain itself, so *.example.com covers cdn.example.com but not example.com.
Next steps
- Apps
- App settings — the per-app settings an editor controls
- Organization settings

