Skip to main content

Your application inventory

Applications in C1 mirror the tools and services your organization uses. You’ll have an application for each piece of software that you manage in C1. On the Apps page there are three applications categories:
  • Managed apps: These are the apps you’ve set up in C1 so it can provide visibility, governance, and automation. You’re actively managing these apps with C1.
  • Unmanaged apps: When you add a connector for an app that is an identity provider (IdP), SSO, or federation provider, the connector discovers the child apps inside of it. These apps are listed as unmanaged. You can move these apps to the Managed state (more on that below) or leave them as-is.
  • Shadow apps: These are apps that have been discovered in your environment but are likely not sanctioned for use by your organization’s corporate IT. Learn more about shadow apps.
All newly created tenants start with a single managed app: the C1 app.

Customize columns and export to CSV

Use Configure columns in the table header to adjust which columns are visible — toggle columns on or off and drag to reorder. Your layout is saved automatically. To export apps data to CSV, click Generate CSV above the Apps table. The Download as CSV drawer opens where you can choose which columns to include before generating the file.

Create a new application

Setting up a new application primarily involves telling C1 where the app’s access data will be sourced from.
A user with the Application Admin or Super Admin role in C1 must complete this task.
1
Navigate to the Apps page and click New application. The Create app drawer opens.
2
Choose the app’s primary source of data — this decides how C1 keeps its accounts and entitlements current:
  • Connector to sync data automatically through a direct integration with the tool or service. Choose a connector from the catalog, or click Browse all to see the full list. You’ll add credentials after the app is created.
  • File to upload access data from a file. Learn more about formatting files for upload. You’ll be prompted to upload the file after the app is created. Also select this option if you want to create a custom app that provisions access using webhooks or helpdesk tickets.
  • External data source to read from a data source your team already connected to C1. Only data sources already connected to your organization are listed.
  • SSO application to create a virtual app sourced from an application discovered in your identity provider. Assignments in your identity provider become the app’s grants.
  • This app is empty to track the app in C1 now and add data later.
3
If you chose Connector as the source, choose how access is managed:
  • Directly through the connector — grants are provisioned and revoked in the app itself.
  • From linked IdP application — access is assigned by an app discovered in your identity provider. Select the IdP application.
This means the application will contain records of both what the identity provider knows about the app (activity and accounts), and the resource and entitlement data pulled from the software itself by the connector.This step doesn’t apply to the other source types.
4
If the app isn’t sourced from an SSO or linked IdP application (which supply their own name), set a Name and, optionally, a Description.
5
Click the pencil icon next to Owners to open the Select owners modal. You can select specific users as owners, or select entitlements — anyone assigned an entitlement you select automatically becomes an owner of the app. You can add or change application owners later.Learn more about app owners.
6
Click Create app. The new application’s details page opens.
Done. From here, you can configure the new app, add connectors or upload data, view resources, entitlements, and accounts, run reports, and more.

Move an unmanaged app to managed

When you add a connector for an app that is an identity provider (IdP), SSO, or federation provider, the connector discovers the apps that are inside of it. These apps are added to the Unmanaged app list.
A user with the Super Administrator role in C1 must complete this task.
If you want to bring an unmanaged app under C1 management so you can start enforcing access controls on it:
1
On the Apps page, click Unmanaged apps.
2
Locate the app and click Manage.Alternatively, use the checkboxes on the left of the screen to select multiple apps, then choose Manage from the bulk actions menu at the bottom of the table.
3
Set the application’s owners. You can set specific users as owners, or set entitlements — anyone assigned an entitlement you select automatically becomes an owner of the app. You can add or change application owners later.Learn more about app owners.
4
Click Manage. The unmanaged app becomes a new managed app.

Customize an app

A Super Admin or an application owner with the Application Admin role in C1 must complete these tasks.

Manage app owners

Application owners can manage the configuration of the applications they own, can be set as reviewers in policies, and are the fallback assignees if an automatic provisioning task on this app fails. You can assign app owners in two ways:
  • By user: Add specific C1 users as direct owners.
  • By entitlement: Add any entitlement from a connected app. All users currently assigned that entitlement automatically become owners of the app, and ownership updates as users are granted or removed from the entitlement.
You can add up to 32 direct user owners and up to 32 entitlements as owners on each app.
Make sure that users who serve as app owners, whether directly or through an entitlement, have either the Application Admin or Super Admin role, as this is required to manage the application.
To edit an app’s owners:
1
On the app’s Overview page, click the pencil icon next to Owners.
2
In the Select owners window, use the Users tab to add or remove user owners, or the Entitlements tab to search for and add entitlement owners.You can mix and match user and entitlement owners as needed.
3
Click Save.
Done. The app’s ownership updates immediately. New owners can manage the app and will receive notifications about it, and any removed owners lose these privileges and notifications.

Edit an app’s name, description, or annotations

Hover over the app’s name, owners, or description at the top of an app’s Overview page and click the pencil icon to update these fields. The drawer also includes an Annotations field, where you can attach custom key/value metadata to the app — useful for tracking cost centers, compliance scope, or IaC management state. Learn more about annotations.

Upload a custom app icon

You can add a logo to an app or change the existing logo.
1
Hover over the app’s name at the top of the Overview page and click the pencil icon. The editing drawer opens.
2
Click Update icon and upload your icon file. You’ll then have the option to center, zoom, and crop the image to form the icon.Icon files must be 1 MB or smaller and in PNG, JPEG, or WebP format.For best results, upload a square, high-resolution image.
3
Click Save icon.
Done. The app’s new icon is now shown throughout C1.

How connectors relate to apps

Connectors provide data ingestion and orchestration functionality for a managed application. View the full connector library to view available connectors and the connectors overview and FAQ page to learn more about how they work.

Should an app have multiple connectors?

In most cases, you’ll only have a single connector for an application. However, it’s not uncommon to need or want to have multiple data sources feeding into one application in C1. For example, you might use a complex tool that requires multiple flat file uploads to fully represent the user and access data. In this case, you would add multiple file connectors to the application, one for each of the files. You can also set up more than one connector of the same type in C1. For example, if your organization has two Okta orgs, add a second Okta connector by repeating the connector’s standard setup flow. During setup, choose whether to add the new connector to an existing app or create a new app for it — optionally linking the new app to an application discovered in your identity provider.

Important notes about managing applications

Delete applications with great caution!

If you delete an IdP, federation, or SSO provider application from C1, all of the applications that have been discovered within it, both those that are unmanaged and those you’ve moved to managed and added connectors to, will also be deleted. You’ll have to manually recreate these apps and re-add connectors to them to continue managing them with C1.