Access
How to share an internal tool without making it public
Four ways to put a small internal app in front of your coworkers and nobody else, what each one costs, and which ones are not access control at all.
You have a working tool. It reads two exports, does the arithmetic your team argues about every month, and it should be a link that eight people open.
The deploy guides skip the question that follows: how do you make it reachable by those eight and nobody else? It matters more than it used to, because these tools now hold real things. Comp numbers. Customer lists. Renewal dates you would not email outside the company.
Here are the four options you will be offered, in the order people try them.
An unguessable URL is not access control
Deploy it somewhere, tell nobody the address, assume nobody finds it.
URLs travel. Someone pastes it into a channel, a ticket, a document that gets exported. The secret is now whatever that system’s permissions are.
And an address you never advertise is still visited. When your app gets its TLS certificate, the domain goes into a public, monitored certificate transparency log, which plenty of people read to see what just appeared. An app with no login in front of it gets opened by strangers.
A shared password stops working on day sixty
One password in front of the whole app. Easy to add, and for three people on one team it genuinely does something.
Then somebody leaves and the password does not, because changing it means telling the other seven. Somebody hands it to a contractor for an afternoon. You cannot tell who opened the thing last week, because everyone is the same user.
Fine for a prototype. Not what you want in front of payroll.
Your company sign-in is right, and it costs an admin
The correct shape: the app sits behind the identity system your company already runs. People get in with the account they have, and leaving the company closes the door.
Every serious platform supports this. What none of them lead with is who has to be in the room to turn it on.
On Google Cloud, putting a Cloud Run service behind Identity-Aware Proxy needs Cloud Run Admin and IAP Policy Admin on the project, and granting one colleague access is another IAM role assignment. On Cloudflare, the app goes behind an Access policy somebody writes in the Zero Trust dashboard. On Replit, it is a plan question: only organizations with an Enterprise plan are able to use SAML SSO.
None of that is unreasonable. These platforms were built for software with a team behind it, where an administrator writing an access policy is a Tuesday. But if you built the tool and you do not hold the project role, you cannot finish this yourself. You can get it running, and then you wait.
Keeping it off the internet entirely
Run it where only the corporate network or the VPN can reach, and let the network be the access control.
This works, and in some regulated environments it is the only thing that gets approved. The costs: somewhere internal to run it, someone to keep that host alive, and every user on the VPN, which rules out the colleague checking something from their phone. You also get no per-person record. Anyone on the network is inside.
What to do this week
If you have an administrator who will help, the company sign-in route is worth the wait. Ask for it by name: the app behind your identity provider, with a group you can add people to yourself. That last part matters. A setup where every new user is another ticket will quietly kill the tool.
If you have no administrator and no VPN, resist the unguessable URL. A shared password on something that holds nothing sensitive is a defensible stopgap. A shared password on everyone’s compensation is not.
The version we are building
Sploot exists for the gap in the middle of that list. One command puts the app online. Sharing it is typing the emails of the people who should have it. Sign-in is on the door before the first boot, so there is no public address at any point. Whoever granted access takes it back.
The point is not that this is faster. It is that the person who built the tool can finish the job, and the security review happens once, about the platform, instead of once per app.
Sploot is in private beta and there is nothing to log into yet. If this is your problem, get on the list and tell us what you would put up first.