Restricting outbound resource access in Airtable
Last updated: August 14, 2026
Plan availability | Business and Enterprise Scale plans only |
Permissions |
|
Platform(s) |
|
Related reading | Airtable enterprise permissions - Learn about internal, external, and guest user types |
Restricting outbound resource access overview
Enterprise admins can control whether members of their organization can access Airtable workspaces, bases, and interfaces owned by external organizations. This closes a gap for security-sensitive customers who need to prevent members from collaborating outside the organization's boundary, even when an external organization shares a resource with them.
This setting lives under Security & compliance in the admin panel, alongside settings like two-factor authentication and IP range restrictions.
Set it once at the organization level, and Airtable enforces it everywhere, blocking new external shares and cleaning up existing ones, so your data stays with the people who should have it.
What you can do as an admin:
Pick a restriction mode for your whole organization: unrestricted, restricted (block all outside access), or custom allow (block by default, with exceptions)
Automatically revoke members' existing access to external resources when you turn a restriction on, not just block new share attempts
Add specific people and resources to an allowlist so approved cross-organization work keeps flowing
Let blocked members request access to a specific resource, then approve or deny each request from the admin panel
Restrictions only apply to your members reaching resources owned by other organizations. Sharing within your own organization is never affected by this setting.
How outbound resource access restriction works
The setting has three modes:
Unrestricted — Allow all members to access external Airtable resources. This is the default.
Restricted — Block all members from accessing external Airtable resources.
Custom allow — Block members from accessing external Airtable resources unless you've added them to an allowlist for that specific resource.
Turning on Restricted or Custom allow mode doesn't just block new access attempts — it also retroactively revokes members' existing access to external workspaces, bases, and interfaces that aren't allowed under the new setting.
Switching to Restricted or Custom allow mode can immediately remove members' access to resources they're currently using. Consider notifying your organization before making this change.
Setting up outbound resource access restriction
Open your Airtable home screen.
Go to Security & compliance.
Find "Access to external resources" and click Edit.
Select Unrestricted, Restricted, or Custom allow.
Click Save.
Managing the allowlist in Custom allow mode
When Custom allow mode is selected, you can grant specific members access to specific external resources:
Under "Add users and resource IDs to allowlist," search for and select the member you want to grant access to.
Enter one or more resource IDs, separated by commas. Resource IDs must start with
wsp(workspace),app(base), orpbd(interface).Click Allow.
Allowed members and their resources appear under the Allowed tab. You can remove a member's access at any time from this tab.
Requesting access to a blocked resource
If a member's access to an external resource is blocked, they can request access from the sign-in or access-denied screen. Their request appears under the Requests tab in the admin panel, where you can approve or deny it.
FAQs
Can I see which external resources a member has requested access to?
Yes. Pending requests appear under the Requests tab in the "Access to external resources" setting, along with the reason the member provided.
Will switching to Restricted or Custom allow mode immediately remove access?
Yes. Members who aren't allowed under the new setting lose access to external workspaces, bases, and interfaces right away. Consider notifying your organization first.
Can I allow one member to access multiple external resources?
Yes. In Custom allow mode, add multiple resource IDs separated by commas when granting access to a member.