Know what was released and who owns it
Applications have an owner, support contact and data classification. Releases are immutable, so a promotion references the reviewed source rather than rebuilding from a branch that may have moved.
Direct to Production is the default deployment workflow. Required checks still apply. A Tenant Admin can configure staged approvals when a human release decision is needed. Agent credentials cannot record human approval decisions.
Separate portal access from origin access
SpringRoll checks membership and environment launch access before returning a running app target. That check governs entry through the App Portal.
Provider hostnames are directly reachable. Portal launch control does not establish complete origin isolation. Protect direct requests with the application or provider's authentication and authorization, and avoid serving sensitive data from an unprotected static page.
An optional Public app page is an introduction. Its publication does not make the running app's audience broader or narrower.
Scope data at the appropriate boundary
For data-product gateway access, the app authenticates with its own identity and queries against an active approved grant. Field, row, volume and expiry controls apply along that gateway path. Source credentials stay server-side.
Connector grants are a separate mechanism and may inject credential values into the deployed application. A write-only configuration interface prevents readback through SpringRoll; it does not make a credential safe if the application itself logs it or sends it to the browser.
Review the exact source, adapter, query operations and app behavior. Revoke stops future gateway use of the grant, not retrieval of previously read or stored data.
Keep governed changes auditable
Governed operations and their audit events are saved together in a transaction. Events record the actor, resource and context of the action. The audit chain is verifiable, and database triggers reject normal update and delete operations.
Tenant-scoped queries and PostgreSQL row-level security provide two layers for the control plane's tenant data. These controls do not substitute for authorization inside an independently deployed app.
Review the app before using real data
Use synthetic data for the first deployment. Check both an allowed and a denied launch, then test the direct provider hostname separately. Inspect browser requests and build logs for exposed credentials.
Review dependency risk, application authorization, data caching and retention, provider configuration and incident ownership for the app's use case. Local code and test coverage support implementation claims; they do not certify a live service or establish a compliance status.
- Confirm the app owner and support route.
- Check the same release in its intended environment.
- Verify each intended data source and grant.
- Document provider and app authentication for direct access.
Bring a concrete security question
Share your app type, data classification, intended audience and hosting requirements with the team. A useful review starts with the specific boundary you need protected and a test that demonstrates it.
For a suspected issue, contact SpringRoll with the affected route and a redacted reproduction. Keep credentials and personal or customer data out of the report.
