Not to whoever built it. Every app runs on the same foundation: single sign-on, roles and permissions, a real people directory and one audit trail. Nobody sets up servers, nobody wires permissions, and it all runs on German and EU infrastructure.
Nobody sets up servers or wires permissions. Every app runs on the same foundation: single sign-on, roles and permissions, a real people directory and an audit trail. Hosting, updates and backups are managed, and it runs on German and EU infrastructure.
The important part is ownership. The app belongs to the company, so it does not leave when the person who made it does, and permissions decide who uses it rather than who happens to have the link.
| Admin | Manager | Member | |
|---|---|---|---|
| View customers | ✓ | ✓ | ✓ |
| Edit invoices | ✓ | ✓ | − |
| Manage people | ✓ | − | − |
| Install apps | ✓ | − | − |
This is where employee-built software normally goes wrong, and it has nothing to do with how good the app was. Someone builds a genuinely useful thing. It runs on their account, in their tool, with a login only they remember. They move on, and a working part of the company quietly becomes an archaeology project.
On Cordango, the app was never theirs. It sits in the company tenant with a named owner and a successor, its users come from the company directory, and its audit trail did not live in an account that just got closed. Someone takes it over the same afternoon, without anyone asking who has the password.
People, teams and managers are the company’s, not a fresh user table per app. Single sign-on means one account to grant and one to revoke. A leaver loses access everywhere at once.
Rights are checked underneath every app, on every read and every write. Not implemented per app by whoever built it, which is how an app usually ends up with a gap nobody noticed.
Who changed what, when, across every app, in one place. You do not gather evidence from five tools with five different log formats and three of them missing.
The same model runs everything on top of it: dashboards, cross-app widgets, personal views and the API all answer to it.
Why a personal view can never widen access →
Cordango is built and hosted in Germany, on EU infrastructure, GDPR-first. Backups, updates and patching are managed, so “who keeps this thing current” is not a question that lands on the person who asked for the app.
The practical effect on a review is that there is one system to assess rather than a growing list of small tools each with their own hosting, their own login and their own data processing agreement. When someone builds a new app, nothing new needs approving. It is the same platform it was last month.
See what a generated app inherits before anyone touches it: your directory, your roles, your audit trail.