Sending an invite for use on their mobile devices has been simple.
The process requires authentication.
Question… Copying the URL app link into an employee’s pc browser required authentication also but since a formal invite through appsheet was not required, is there anything stopping anyone from using our app URL along with a random BOX cloud account to gain access to our app?
In summary, I assumed the specific invite was my security over uninvited users that may have access to our app URL. What stops an uninvited user from getting our app URL and accessing our app?
Since sign in is required and the URL app user is listed as an approved user then only a BOX cloud account associated with that email can utilize the our app URL, correct?
I had my app set to “Require user sign in” and an un-invited private email appeared as another user that was not approved but was counted by AppSheet as another user. So how does that happen?