Glossary

RBAC

Who can open which apps, decided by role. The formal name is role-based access control.

Definition

When you share an app with your team, the first practical question is who can open which apps. That pattern is often called RBAC, short for role-based access control. People get a role (for example admin, creator, or member), and the role decides what they can open and change. Company login / SSO proves who someone is. RBAC uses that identity to limit apps and actions. It is access control described in everyday team-sharing terms.

Why it matters

Internal tools spread quickly once AI makes them easy to build. Without clear rules for who can open which apps, a contractor might see a finance model, or every signed-in person might edit a live checklist. RBAC keeps private hosting usable at team scale and reduces accidental exposure from AI-generated apps.

How Croft fits

Croft leads with sharing: invite people, then decide who can open which apps. Team plans include roles and permissions so admins, creators, and members are not all the same. Apps and data sources start locked down. See Access control, SSO, Security, and the roles docs for the day-to-day model.

Keep reading

FAQ

Frequently asked questions

What is RBAC in plain English?

Rules for who can open which apps based on their role on the team. Sign-in proves identity; RBAC decides access.

How is RBAC different from SSO?

SSO (company login) proves who someone is. RBAC decides what that person is allowed to open and do.

How do I share an app with only some of my team on Croft?

Invite those people and grant them access to that app. Keep everyone else without access. That is RBAC in practice.

Stake out your croft.

Your team's first app could be live before lunch.

Get your croft

7 days free, no card to start. From $24/month - cancel anytime and take everything with you.