Enterprise · Platform Foundations3 WORKSHOPS · 4 TIERS · MICROSOFT OR GOOGLE IDENTITY

No more Wild-West.
QREW's guardrails unlock safe innovation.

The AppSheet Landing Zone is a standardized, governance-first, AppSheet Platform Setup methodology. Microsoft Entra ID / Google Groups stays your identity provider. MDM configuration to securely distribute. Your field teams get a mobile-native platform — and IT gets a managed perimeter instead of a spreadsheet nobody is watching.

Setup your environment DELIVERED BY GOOGLE DEVELOPER EXPERTS

Shadow-IT isn't a tooling problem.
It's the absence of a safe place to build.

When there's no sanctioned environment, people build anyway — in personal accounts, on unmanaged devices, against data nobody is auditing. A landing zone is the standard answer from cloud infrastructure, applied to low-code: you deploy the guardrails first, then invite people in.

The result is that IT stops policing tools and starts operating a platform. Builders get somewhere legitimate to work. Security gets a perimeter it can describe in a review.

Tenant HarmonyGoogle & Microsoft

Whether you run Microsoft or Google for collaboration, you can manage innovation at scale with AppSheet!

Identity

Entra or Google Groups

Users sign in with the Microsoft / Google credentials they already have. AppSheet federates to the source of truth — no second directory, no separate password, no shadow account to deprovision.

Access

Your security groups drive access

AppSheet teams map one-to-one to Entra ID / Google Group security groups. Add someone to a group and their access follows automatically

Devices

BYO MDM

AppSheet supports a cross-platform distribution model: Web, iOS and Android. QREW helps you configure distribution and app launchers to keep device access secure and compliant.

What gets deployedRAMP-ALIGNED

Four tiers.
Nobody starts with production access.

A new employee lands in Viewer and earns their way up. Each tier is a real boundary with its own policy set, not a label — so the question "who can touch production data?" has a one-sentence answer.

TierWhat it's forThe control
ViewerConsume apps. Build nothing.Export blocked · external sharing blocked
SandboxLearn and experiment safely.Limited features and scope of impact
Citizen DeveloperBuild real apps against real data.Governed, monitored, promotable
IT AdminOwn the platform.Full policy and audit authority
The four-tier AppSheet team structureA stack of four tiers, widest at the bottom and narrowing toward the top as authority increases. From the bottom: Viewer, who consumes apps and builds nothing; Sandbox, for learning safely; Citizen Developer, who builds against real data; and IT Admin, who owns policy and audit.IT ADMINOwns policy & auditCITIZEN DEVELOPERBuilds on real dataSANDBOXLearns safelyVIEWERConsumes, builds nothingAUTHORITY
How it runsFOUNDATION FIRST, THEN SCALE
PHASE 01

The Foundation

Three workshops that stand up the secure perimeter. This is the minimum viable landing zone — at the end of it, you can safely let people in.

  • SSO federation to Microsoft Entra ID or Google Groups, with domain verification handled alongside your admins.
  • The four-tier team structure deployed and mapped to your existing security groups.
  • A standardized governance policy set, deployed as code rather than hand-configured.
  • Data-exfiltration controls — export and external sharing blocked in the lower tiers.
  • Secure distribution across web, iOS, and Android — configured against the MDM you already run.
PHASE 02

Day-2 Operations

Once the platform is live, the problem changes from access to operations: knowing what's been built, keeping it pointed at the right data, and connecting it to the systems that matter.

  • Audit logs streamed to BigQuery for long-term retention and security analysis.
  • A Looker Studio control tower for adoption, sync failures, and usage trends.
  • App Lifecycle controls to handle termination and transfer of apps between owners.
  • An App Registry that tracks licence usage, compliance, lifecycle reviews, and creator certifications in one place.
  • IT-owned shared data sources, so app creators build against a governed source of truth rather than their own copies.
  • Integration Connectors configured to reach Workday, Salesforce, Cloud SQL, BigQuery, and the rest of your systems securely.
What you keepYOURS, NOT OURS
Runbook

The Modernization Runbook

A written guide to your specific configuration — team IDs, security group mappings, and the reasoning behind each. Your team can operate the platform without us.

Policy map

The Governance Map

A plain-English account of what is allowed and blocked for each tier. Written to be read by people who will never open the admin console.

For the CISO

The Architecture Review

We shepherd AppSheet through your security review so all IT stakeholders can endorse the platform.

The zone is the foundation.
The champions are the point.

A governed environment is worth having because of what it lets you do next: turn your own employees into the people who build your software. Most engagements run the Landing Zone first, then the Champion Program inside it.