Skip to content

For engineering leaders

Get internal tools off your roadmap without losing control of them

Every team wants an admin panel, an approval flow, a dashboard. ToolJet lets them build those themselves, from a prompt or a coding agent, inside a platform your team governs: single sign-on, permissions to the query, audit logs, environments and Git. Your engineers review and promote; they stop writing the tenth CRUD app.

  • Retire one-off internal apps
  • Standardise auth and access
  • Govern agent-built software
Example Engineering leaders app · illustrative data
Internal apps · Platform viewWorkspace overviewSSOAudit onProduction
Apps in production6312 added this quarter
Built by business teams71%reviewed by platform eng
Auth exceptions0all apps on SSO + roles
AppOwnerEnvironmentStatus
Refund approvalsSupport opsProductionHealthy
Vendor onboardingProcurementStagingIn review
On-call rotaPlatform engProductionHealthy
Churn risk dashboardCustomer successDevelopmentAgent draft

Which apps query the customers table, and who can run those queries?

4 apps, 2 roles · permissions report ready for review

40,000+stars on the open-source core
AICPA SOCISO 27001
SOC 2 Type IIISO 27001 and GDPR · Visit the trust centre
Your infrastructureCloud, VPC, on-premise or air-gapped
100+ connectorsplus any REST or gRPC endpoint

No engineering ticket needed

Describe the tool you need. ToolJet builds it.

Type what you want in plain language. ToolJet generates the pages, queries and logic as a working app. Connect your data, set who can see what, and review the generated logic before publishing. Edit the app on the canvas afterwards.

  • Working app, not a mockup
  • Review access rules before publishing
  • Free to start, per-builder pricing
Enter to build · Shift+Enter for a new line

Runs on the stack your team already operates

  • PostgreSQL
  • Snowflake
  • BigQuery
  • MongoDB
  • REST API
  • Jira
  • Slack
  • Microsoft 365
Browse all integrations

Have developers? They can build the same apps fromClaude CodeCodexCursorGitHub CopilotGrok Buildthrough the ToolJet plugin

What moves off the engineering backlog

The requests that arrive as tickets and leave as half-maintained side projects.

Admin and back-office panels

Business teams build CRUD over production data with row-level rules; engineering reviews the queries, not the UI.

Approval workflows

Access requests, spend approvals, change sign-offs, with the decision trail your auditors ask for.

Operational dashboards

Live views over your warehouse and services, owned by the team that reads them.

Customer-facing support tools

Lookups and guarded actions across your database, billing and ticketing, without exposing credentials.

Scheduled jobs and integrations

On Self-hosted, build webhook and scheduled workflows with JavaScript logic, data-source nodes and run logs.

Agent-built prototypes

Product and ops teams draft apps from Claude Code or Codex through the plugin; your team promotes what is worth keeping.

How teams roll it out

  1. 01

    Stand it up where you want it

    ToolJet Cloud, or self-hosted on Kubernetes, Helm, OpenShift or Docker in your VPC or air-gapped. Connect SSO and SCIM on day one.

  2. 02

    Connect data once, govern it centrally

    Data sources are configured by platform engineering with environment-scoped credentials. Builders use them; they never see the secrets.

  3. 03

    Let teams build, keep the review

    Business teams and agents build in development. Your engineers review queries and permissions, then promote through staging to production.

  4. 04

    Keep it in version control

    Git sync puts app definitions in your repository. Version history and rollback cover the rest.

In production

Teams already running on ToolJet

Governance is the platform

One control plane for every internal app

Identity, permissions, secrets, environments and audit apply to every app, whether a person built it on the canvas or an agent built it from a prompt.

Identity from your directory

SAML, OIDC and LDAP; groups map to ToolJet roles; SCIM provisions and deprovisions.

Least privilege by default

Workspace, app, page, component and query permissions with row-level security. Builders cannot grant what they do not hold.

Audit logs you can export

Platform events with actor and timestamp, exportable to your SIEM. MCP actions use the connecting user's permissions; review available event details in your audit logs.

Environments and Git

Dev, staging and production with scoped credentials; Git sync; versioned releases with rollback.

Security and governance features vary by plan. Workflows and Agent Builder are available on Self-hosted only; BYOK is a Self-hosted Enterprise add-on. Compare plan availability.

Two ways to get there

Build it yourself, or bring our engineers in

Self-serve

Your team, your pace

Start free. Describe the tool, refine it on the canvas, and ship it under your own access rules. Start with one app, then test it with your team before rolling it out.

Start free

Professional services

Forward-deployed engineers, embedded with your team

When the timeline is fixed or the process is tangled, our engineers build alongside you: scoped delivery, production-ready apps, and knowledge transfer so your team owns the result.

Talk about a project

Questions engineering leaders ask before they start

How do we avoid a sprawl of unmaintained apps?

Every app is visible in one workspace with an owner, an environment and a permission set. Data sources are shared and centrally credentialed, so there is nothing to rotate in fifty places. Git sync and version history mean an app abandoned by its builder is still a readable, recoverable definition.

What do our engineers still have to do?

Configure data sources and SSO once, then review and promote. Business teams build in development; the review step is on queries and permissions, which is where the risk lives. Engineers write code only where a workflow or component genuinely needs it.

Can we run it inside our network?

Yes. Self-host on Docker, Kubernetes, Helm or OpenShift, in your VPC, on-premise or air-gapped. The AI features can run against your own model keys or an on-premise gateway.

How does agent-built software stay safe?

The ToolJet plugin gives agents structured access to the app model through your ToolJet instance, scoped to the connecting user's permissions. It never receives database credentials. Changes land in development and follow your promotion process.

What does it cost as usage grows?

Pricing is per builder, not per user. Every plan includes an end-user allowance and Enterprise includes unlimited end users, so rolling a tool out widely does not add a seat for every viewer. The pricing page lists the allowance on each plan.

Give every team a way to build that you would sign off on

See the control model on your own data. Thirty minutes with an engineer, not a sales deck.

Page updated