Application Owners

Application owners are users who have full management rights for an application in AZExecute. This multi-owner model allows you to distribute application management responsibilities across your team while maintaining proper access control and audit trails.

Under General, use Owners to manage the owner list and Requests to review ownership requests. On smaller screens these tabs use a vertical icon rail: the people icon opens Owners and the person-plus icon opens Requests. Counts remain visible beside the icons.


Owner vs. Viewer Access

AZExecute implements a two-tier access model for applications:

Owner Access

Users listed as application owners have full management rights:

Configure secret rotation settings and integrations

Manage certificate lifecycle and Key Vault integration

Manually trigger secret or certificate rotation

Add or remove other owners

Review and approve incoming permission requests

Create permission requests to other applications

Change application state (Active, Disabled, Deleted)

View application logs and execution history


Viewer Access (Read-Only)

Users who are not owners can still view applications if "Show All Applications" is enabled by tenant administrators:

View application configuration (secrets tab, certificates tab)

View permissions, scopes, and app roles

See who the owners are

Cannot make any configuration changes

Cannot trigger rotations or access sensitive data

Can request to become an owner

Visibility Note: If "Show All Applications" is disabled, users can only see applications where they are listed as owners. Tenant administrators can always see all applications.


Adding Owners

There are two ways to add owners to applications:

Method 1: From Application Details

1. Navigate to your application's details page

2. Go to the General tab

3. Open the Owners tab

4. Click Add Owner

5. Search for users in Owners, select their rows, and review the list under Selected

6. Click Add with the selected owner count to confirm


Method 2: Bulk Add from Applications List

Add the same owner to multiple applications at once:

1. Navigate to the Applications list page

2. Select multiple applications using the checkboxes

3. Click Add Owners button (appears when applications are selected)

4. Search for and select the user

5. User is added as owner to all selected applications

Efficiency Tip: Use bulk add when onboarding new team members or reorganizing application ownership across multiple apps.


Removing Owners

To remove an owner from an application:

1. Navigate to the application's General tab

2. Find the owner in the General → Owners section

3. Click the Remove button next to their name

4. Confirm the removal

5. User immediately loses owner access

Important: An application must have at least one owner. You cannot remove the last owner. Add another owner first before removing the current one.

Self-Service Limitation: You can remove yourself as an owner, but only if there's at least one other owner. This prevents accidentally orphaning applications.


Requesting Owner Access

Users who have viewer access can request to become owners through a formal approval workflow:

Creating an Access Request

1. Navigate to the application you want to manage

2. You'll see a read-only warning banner at the top

3. Click Request Access button in the applications list

4. Provide justification for why you need owner access

5. Submit the request



Approval Process

1

Request Submitted

Your request is sent to all current application owners

2

Email Notification

Owners receive email with your justification and link to review

3

Owner Review

Any owner can approve or deny your request

4

Approval/Denial

You receive email notification of the decision with any comments

5

Access Granted (if approved)

You're automatically added as owner with immediate access


Request Status

While your request is pending, the application shows:

� A "Pending" badge instead of the "Request Access" button

� You cannot submit duplicate requests while one is pending

� You still have read-only access during the review period

Tip: Provide detailed justification explaining your role, responsibilities, and specific tasks you need to perform. This helps owners make informed approval decisions.


Managing Access Requests (For Owners)

As an application owner, you can review and process owner access requests:

Viewing Pending Requests

Pending access requests are shown in multiple places:

Email notifications when requests are submitted

Warning banner on application General tab if pending requests exist

Owners section shows count of pending requests


Approving Requests

1. Navigate to the application's General tab

2. Open Requests and review the pending request details (user, justification, date)

3. Click Approve on the request

4. Optionally add a comment for the requester

5. User is immediately added as owner


Denying Requests

1. Click Deny on the request

2. Provide a reason for denial (shown to requester)

3. Consider providing guidance or alternative solutions

4. Requester receives email with your decision and comments


Automatic Assignment During Import

When you import an application into AZExecute, you're automatically added as the first owner:

Direct Import: You become the sole owner immediately

Request-Based Import: You become owner when the request is approved

Best Practice: Add other team members as owners shortly after import to ensure continuity if you leave the organization or change roles.


Best Practices

Maintain at least two owners per application

Ensures continuity if one owner is unavailable or leaves the organization

Add owners from the same team

Owners should understand the application's purpose and requirements

Review access requests promptly

Respond within 24-48 hours to avoid blocking team members' work

Periodically review owner list

Remove owners who have left the team or changed responsibilities

Use bulk add for new team members

When onboarding, add the person to all relevant applications at once

Provide helpful denial reasons

When denying access requests, explain why and suggest alternatives if appropriate

Consider view-only access when appropriate

Not everyone needs owner rights - viewer access may be sufficient for some users


Tenant Administrator Capabilities

Users with the Tenant Administrator role have special capabilities:

View all applications regardless of owner list or "Show All Applications" setting

Full management rights to all applications without being listed as owner

Add/remove owners from any application

Recover orphaned applications by adding owners if all were removed

Configure "Show All Applications" setting that controls viewer access

Note: Tenant Administrator is a powerful role. Assign it only to users who need organization-wide application management capabilities.

An unhandled error has occurred. Reload 🗙
An unhandled error has occurred. Reload 🗙