> For the complete documentation index, see [llms.txt](https://docs.siit.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.siit.io/data-management/apps.md).

# Apps

Your app inventory: every tool employees use, with ownership, lifecycle, cost, and security attributes. Route requests by app, pick approvers automatically, and trigger provisioning in your IdP

Applications are your app inventory: every tool employees use, along with ownership, lifecycle, costs, and security attributes.

**Why it matters**

* Clear ownership: know who approves access and who to notify during incidents.
* Better workflows: route requests by app, pick approvers automatically, and trigger provisioning in tools like Okta/Azure AD/Google Workspace.
* Visibility: analyze usage, categories, and costs.

Manage application fields Customize the fields that describe apps (and their visibility). Common fields include:

* Owner, Teams, Category, Lifecycle (e.g., Active, Security review)
* Sensitive data (Y/N), Status page URL
* Contract details (renewal date, vendor, currency)
* Annual cost, Licenses, Jurisdiction, Hosting Turn fields on/off and set the structure that fits your governance.

**Inventory and profiles**

* List: search and filter apps by category, owner, lifecycle, or cost.
* Profile: see the app’s details, owners, related teams, and linked requests. From here, open the status page or start/approve access workflows.

**Active Users**

Every app profile has an **Active Users** tab: a live, reconciled view of everyone who currently has access, pulled together from every source Siit knows about.

* **Always up to date** : a grant or revocation through your IdP or through App Access updates the list immediately. Siit reference-counts access, so someone stays listed as long as any source still grants it, and drops off only once the last one is gone.
* **Origin at a glance** : each person shows how they got access: an IdP provider, App Access, or a direct admin add. Access can come from more than one source at once.
* **Usage as a source** : with Microsoft Entra ID connected, signing in to an app through SSO makes someone a user of that app in Siit, with or without an assignment. Usage based memberships expire when the person stops signing in, so the list stays aligned with real usage.
* **Full activity history** : an activity timeline follows every event behind the current state: request creation, approvals, manual and automatic actions, provisioning failures, cancellations, and planned deprovisioning.

<figure><img src="https://451675063-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fz9xmM8V3atukfr2XaElR%2Fuploads%2FRD45Bzf2geedifuqiy2f%2FCleanShot%202026-08-06%20at%2013.58.28%402x.png?alt=media&amp;token=2bffacab-0f15-43c5-b6d9-8455891a8df1" alt=""><figcaption></figcaption></figure>
