Admin and back-office panels
Business teams build CRUD over production data with row-level rules; engineering reviews the queries, not the UI.
For engineering leaders
Every team wants an admin panel, an approval flow, a dashboard. ToolJet lets them build those themselves, from a prompt or a coding agent, inside a platform your team governs: single sign-on, permissions to the query, audit logs, environments and Git. Your engineers review and promote; they stop writing the tenth CRUD app.
| App | Owner | Environment | Status |
|---|---|---|---|
| Refund approvals | Support ops | Production | Healthy |
| Vendor onboarding | Procurement | Staging | In review |
| On-call rota | Platform eng | Production | Healthy |
| Churn risk dashboard | Customer success | Development | Agent draft |
Which apps query the customers table, and who can run those queries?
4 apps, 2 roles · permissions report ready for review
No engineering ticket needed
Type what you want in plain language. ToolJet generates the pages, queries and logic as a working app. Connect your data, set who can see what, and review the generated logic before publishing. Edit the app on the canvas afterwards.
Runs on the stack your team already operates
Have developers? They can build the same apps fromthrough the ToolJet plugin
The requests that arrive as tickets and leave as half-maintained side projects.
Business teams build CRUD over production data with row-level rules; engineering reviews the queries, not the UI.
Access requests, spend approvals, change sign-offs, with the decision trail your auditors ask for.
Live views over your warehouse and services, owned by the team that reads them.
Lookups and guarded actions across your database, billing and ticketing, without exposing credentials.
On Self-hosted, build webhook and scheduled workflows with JavaScript logic, data-source nodes and run logs.
Product and ops teams draft apps from Claude Code or Codex through the plugin; your team promotes what is worth keeping.
ToolJet Cloud, or self-hosted on Kubernetes, Helm, OpenShift or Docker in your VPC or air-gapped. Connect SSO and SCIM on day one.
Data sources are configured by platform engineering with environment-scoped credentials. Builders use them; they never see the secrets.
Business teams and agents build in development. Your engineers review queries and permissions, then promote through staging to production.
Git sync puts app definitions in your repository. Version history and rollback cover the rest.
In production
Governance is the platform
Identity, permissions, secrets, environments and audit apply to every app, whether a person built it on the canvas or an agent built it from a prompt.
SAML, OIDC and LDAP; groups map to ToolJet roles; SCIM provisions and deprovisions.
Workspace, app, page, component and query permissions with row-level security. Builders cannot grant what they do not hold.
Platform events with actor and timestamp, exportable to your SIEM. MCP actions use the connecting user's permissions; review available event details in your audit logs.
Dev, staging and production with scoped credentials; Git sync; versioned releases with rollback.
Security and governance features vary by plan. Workflows and Agent Builder are available on Self-hosted only; BYOK is a Self-hosted Enterprise add-on. Compare plan availability.
See the full control model Compare plans Talk to an engineer
Two ways to get there
Self-serve
Start free. Describe the tool, refine it on the canvas, and ship it under your own access rules. Start with one app, then test it with your team before rolling it out.
Start freeProfessional services
When the timeline is fixed or the process is tangled, our engineers build alongside you: scoped delivery, production-ready apps, and knowledge transfer so your team owns the result.
Talk about a projectEvery app is visible in one workspace with an owner, an environment and a permission set. Data sources are shared and centrally credentialed, so there is nothing to rotate in fifty places. Git sync and version history mean an app abandoned by its builder is still a readable, recoverable definition.
Configure data sources and SSO once, then review and promote. Business teams build in development; the review step is on queries and permissions, which is where the risk lives. Engineers write code only where a workflow or component genuinely needs it.
Yes. Self-host on Docker, Kubernetes, Helm or OpenShift, in your VPC, on-premise or air-gapped. The AI features can run against your own model keys or an on-premise gateway.
The ToolJet plugin gives agents structured access to the app model through your ToolJet instance, scoped to the connecting user's permissions. It never receives database credentials. Changes land in development and follow your promotion process.
Pricing is per builder, not per user. Every plan includes an end-user allowance and Enterprise includes unlimited end users, so rolling a tool out widely does not add a seat for every viewer. The pricing page lists the allowance on each plan.
See the control model on your own data. Thirty minutes with an engineer, not a sales deck.
Page updated