> For the complete documentation index, see [llms.txt](https://oten.gitbook.io/identity-support/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://oten.gitbook.io/identity-support/user-guide/account-management/app-consent-management.md).

# App Consent Management

### Scope <a href="#scope" id="scope"></a>

View, inspect, and revoke access for **third-party apps and services** connected to your account from the **Apps & Services** page.

* In scope: viewing a scrollable list of connected apps, viewing app detail (permissions, access history, authorization method), revoking app access with confirmation, filtering access history
* Out of scope: granting new app connections (handled during the app's OAuth consent flow), admin-level consent policies, modifying individual permission scopes without full revocation

***

### I am new. Where should I start? <a href="#i-am-new-where-should-i-start" id="i-am-new-where-should-i-start"></a>

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FlwLoU0DPd5hRkqGdXrtJ%2FScreenshot%202026-07-21%20at%2012.50.57%E2%80%AFPM.png?alt=media&amp;token=660aac52-976e-4816-b2e5-1d2d1f6fa5ff" alt=""><figcaption></figcaption></figure>

Over time, you connect various third-party apps and services to your account. Each connection grants that app certain permissions to access your data. The Apps & Services page is your central hub for auditing and managing these connections.

* **Connected apps list** shows every third-party app you have authorized, with its icon, name, and optional provider
* **App detail page** reveals exactly what permissions each app holds, when it last accessed your data, and a full access history with timestamps, devices, and locations
* **Revoke access** lets you permanently withdraw an app's ability to access your data with a single action

Key things to know:

* Each connection is treated independently. If you connected the same app multiple times (e.g., multiple Jira tenants), each appears as a separate item.
* Default (built-in) apps cannot be revoked. The revoke option is not available for them.
* Revoking access is immediate. There is no grace period or undo.
* Only apps connected to your own account are visible. You cannot see other users' connections.

***

### Purpose <a href="#purpose" id="purpose"></a>

* Audit which third-party apps have access to your account and data
* Review the specific permissions you granted to each app
* Inspect when and from where each app accessed your data
* Permanently revoke an app's access when you no longer need it or trust it

***

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

Before managing your app consents, ensure that:

* You are signed in to your account
* You have previously connected at least one third-party app (otherwise the page shows an empty state)

***

### I already understand. How do I proceed step by step? <a href="#i-already-understand-how-do-i-proceed-step-by-step" id="i-already-understand-how-do-i-proceed-step-by-step"></a>

#### Step 1: Open the Apps & Services Page <a href="#step-1-open-the-apps--services-page" id="step-1-open-the-apps--services-page"></a>

* Sign in to your account
* Navigate to **Account Settings**
* Select **Apps & Services** (or navigate from the Data & Privacy page's Apps & Services section)
* The system displays a scrollable list of all connected third-party apps

***

#### Step 2: Review Your Connected Apps <a href="#step-2-review-your-connected-apps" id="step-2-review-your-connected-apps"></a>

* The page shows each app with its **icon**, **name**, and optionally its **provider**
* A counter at the top shows the **total number** of connected apps
* If you have multiple connections from the same app (e.g., two different Jira workspaces), each appears as a separate item in the list
* Scroll through the list to see all your connections. The list loads all items in a single scrollable view.
* If you have **no connected apps**, the page displays: "You have not connected any apps or services yet." and the counter shows zero.

***

#### Step 3: View App Details <a href="#step-3-view-app-details" id="step-3-view-app-details"></a>

* Click on any app in the list to open its **App Detail** page
* The detail page displays:
  * **App icon and name**
  * **Granted permissions**: a readable list of all access rights you authorized (e.g., read profile, access files)
  * **Authorization method**: how the app was connected (e.g., "Connected via Google OAuth")
  * **Last activity**: the most recent timestamp, IP address, and location where the app accessed your data

***

#### Step 4: Review App Access History <a href="#step-4-review-app-access-history" id="step-4-review-app-access-history"></a>

* On the App Detail page, scroll to the lower section to see the **access history**
* Each access event shows:
  * Event type and description
  * Timestamp (format: dd/mm/yyyy - hh:mm:ss)
  * Status of the access attempt
  * IP address and approximate location
  * Device information
  * Risk indicators (if applicable): new device, new location, unusual app usage, high-risk login
* Events are listed in **chronological order, newest first**
* Use the **filters** to narrow results by event type, status, or date range
* If no activity is recorded, the section shows: "No activity has been recorded for this app."

***

#### Step 5: Revoke an App's Access <a href="#step-5-revoke-an-apps-access" id="step-5-revoke-an-apps-access"></a>

* On the App Detail page, click the **Remove Access** button
* A confirmation modal appears with the title **"Remove access?"** and the warning: "This app will no longer have access to your data, and connected features may stop working."
* The modal provides two options:
  * **Remove** (destructive button): confirms revocation
  * **Cancel**: dismisses the modal without revoking
* You can also close the modal by clicking the **X button** or clicking **outside the modal**. In both cases, access remains active.

***

#### Step 6: Confirm or Cancel Revocation <a href="#step-6-confirm-or-cancel-revocation" id="step-6-confirm-or-cancel-revocation"></a>

* If you click **Remove**:
  * The system revokes the app's access **immediately**
  * You are redirected to the Apps & Services list page
  * The removed app no longer appears in the list
  * A success message confirms the revocation
* If you click **Cancel**, **X**, or outside the modal:
  * The modal closes
  * You remain on the App Detail page
  * The app's access remains fully active

***

#### Step 7: Handle Loading and Error States <a href="#step-7-handle-loading-and-error-states" id="step-7-handle-loading-and-error-states"></a>

* While the app list is loading, a **skeleton loader or spinner** appears
* If the system fails to load the app list (network or server error), an error message appears with a **Retry** action
* If you are offline, the system shows: "You're offline" with a retry option
* If app history fails to load on the detail page, an error message and **Retry button** appear

***

### Important Notes <a href="#important-notes" id="important-notes"></a>

* **Revocation is permanent and immediate.** Once you confirm, the app loses access instantly. There is no undo or grace period. If you need the app again, you must re-authorize it through the app's connection flow.
* **Default apps cannot be revoked.** Certain built-in apps are protected and do not show the Remove Access option. This is currently a hardcoded restriction.
* **Data isolation is enforced.** You can only see and manage apps connected to your own account. No other user's connections are ever visible to you.
* **Multiple connections are separate.** If you authorized the same app for different tenants or workspaces, each connection is independent. Revoking one does not affect the others.
* **All labels support your selected language.** The Apps & Services page and app detail page adapt to your preferred language setting (English or Vietnamese).
* **Disconnecting an app may break features.** Third-party features that rely on the revoked permissions will stop working immediately after revocation.

***

### Summary <a href="#summary" id="summary"></a>

| Item                | Description                                                       |
| ------------------- | ----------------------------------------------------------------- |
| Page location       | Account Settings > Apps & Services                                |
| List content        | App icon, name, optional provider, total count                    |
| Detail content      | Icon, name, permissions list, authorization method, last activity |
| Access history      | Timestamp, device, location, IP, status, risk indicators          |
| History order       | Newest first (chronological)                                      |
| History filters     | Event type, status, date range                                    |
| Revoke action       | Remove Access button > confirmation modal > immediate revocation  |
| Revoke confirmation | Title: "Remove access?", destructive Remove button + Cancel       |
| Default apps        | Cannot be revoked                                                 |
| Empty state         | "You have not connected any apps or services yet."                |
| Error state         | Error message with Retry action                                   |
