Application Owners
Application owners are users who have full management rights for an application in AZExecute. This multi-owner model allows you to distribute application management responsibilities across your team while maintaining proper access control and audit trails.
Under General, use Owners to manage the owner list and Requests to review ownership requests. On smaller screens these tabs use a vertical icon rail: the people icon opens Owners and the person-plus icon opens Requests. Counts remain visible beside the icons.
Owner vs. Viewer Access
AZExecute implements a two-tier access model for applications:
Owner Access
Users listed as application owners have full management rights:
Configure secret rotation settings and integrations
Manage certificate lifecycle and Key Vault integration
Manually trigger secret or certificate rotation
Add or remove other owners
Review and approve incoming permission requests
Create permission requests to other applications
Change application state (Active, Disabled, Deleted)
View application logs and execution history
Viewer Access (Read-Only)
Users who are not owners can still view applications if "Show All Applications" is enabled by tenant administrators:
View application configuration (secrets tab, certificates tab)
View permissions, scopes, and app roles
See who the owners are
Cannot make any configuration changes
Cannot trigger rotations or access sensitive data
Can request to become an owner
Adding Owners
There are two ways to add owners to applications:
Method 1: From Application Details
1. Navigate to your application's details page
2. Go to the General tab
3. Open the Owners tab
4. Click Add Owner
5. Search for users in Owners, select their rows, and review the list under Selected
6. Click Add with the selected owner count to confirm
Method 2: Bulk Add from Applications List
Add the same owner to multiple applications at once:
1. Navigate to the Applications list page
2. Select multiple applications using the checkboxes
3. Click Add Owners button (appears when applications are selected)
4. Search for and select the user
5. User is added as owner to all selected applications
Removing Owners
To remove an owner from an application:
1. Navigate to the application's General tab
2. Find the owner in the General → Owners section
3. Click the Remove button next to their name
4. Confirm the removal
5. User immediately loses owner access
Requesting Owner Access
Users who have viewer access can request to become owners through a formal approval workflow:
Creating an Access Request
1. Navigate to the application you want to manage
2. You'll see a read-only warning banner at the top
3. Click Request Access button in the applications list
4. Provide justification for why you need owner access
5. Submit the request
Approval Process
1
Request Submitted
Your request is sent to all current application owners2
Email Notification
Owners receive email with your justification and link to review3
Owner Review
Any owner can approve or deny your request4
Approval/Denial
You receive email notification of the decision with any comments5
Access Granted (if approved)
You're automatically added as owner with immediate accessRequest Status
While your request is pending, the application shows:
� A "Pending" badge instead of the "Request Access" button
� You cannot submit duplicate requests while one is pending
� You still have read-only access during the review period
Managing Access Requests (For Owners)
As an application owner, you can review and process owner access requests:
Viewing Pending Requests
Pending access requests are shown in multiple places:
Email notifications when requests are submitted
Warning banner on application General tab if pending requests exist
Owners section shows count of pending requests
Approving Requests
1. Navigate to the application's General tab
2. Open Requests and review the pending request details (user, justification, date)
3. Click Approve on the request
4. Optionally add a comment for the requester
5. User is immediately added as owner
Denying Requests
1. Click Deny on the request
2. Provide a reason for denial (shown to requester)
3. Consider providing guidance or alternative solutions
4. Requester receives email with your decision and comments
Automatic Assignment During Import
When you import an application into AZExecute, you're automatically added as the first owner:
Direct Import: You become the sole owner immediately
Request-Based Import: You become owner when the request is approved
Best Practices
Maintain at least two owners per application
Ensures continuity if one owner is unavailable or leaves the organizationAdd owners from the same team
Owners should understand the application's purpose and requirementsReview access requests promptly
Respond within 24-48 hours to avoid blocking team members' workPeriodically review owner list
Remove owners who have left the team or changed responsibilitiesUse bulk add for new team members
When onboarding, add the person to all relevant applications at onceProvide helpful denial reasons
When denying access requests, explain why and suggest alternatives if appropriateConsider view-only access when appropriate
Not everyone needs owner rights - viewer access may be sufficient for some usersTenant Administrator Capabilities
Users with the Tenant Administrator role have special capabilities:
View all applications regardless of owner list or "Show All Applications" setting
Full management rights to all applications without being listed as owner
Add/remove owners from any application
Recover orphaned applications by adding owners if all were removed
Configure "Show All Applications" setting that controls viewer access