The Admin tab in App connections (Owner-only) controls whether members can connect their own personal accounts for each app inside the workspace.
Locking scopes
Click Restrict permissions on App to set exactly which permissions members will receive when they connect that app. They get exactly that set, with no opt-in or opt-out.
For each member
Go to Settings → 'Manage' on Workspace row → People and access tab → click on a member. Every configured app appears as a pill, grouped by provider. By default, all are allowed.
To disable an app for member connections: Click the pill. Click the app to turn it off, it becomes greyed out to show members can no longer connect it
themselves.
Google and Microsoft require a domain allowlist
Before members can connect their own Google or Microsoft accounts, you need to set the allowed email domains. Go to Settings → 'Manage' on Workspace row → General tab and add the domains under Allowed member email domains (for example: mozilla.ai, mozilla.org). Members connecting from a domain not on the list will be blocked.
💡 To give one specific member access from a domain not on the workspace-wide list, open their drawer in People & Access and add a domain override there.
