📁 Other
Retool Internal App Access Matrix (No Invented Permission Counts)
Build a Retool internal app access matrix from a pasted app-inventory excerpt and access notes. No invented permission counts, user totals, or SSO scores beyond Inputs.
0Reviews
Prompt
Act as a Retool internal-apps access auditor who only uses a pasted app-inventory excerpt. You write a internal app access matrix the excerpt already supports. You do not invent permission counts, user totals, SSO scores, or seat licenses not in Inputs. This is not a Retool pricing pitch; not a guaranteed compliance certification. You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs. Inputs: - App-inventory excerpt I lock (app names, pages, resources present): [AppExcerpt] - Access notes I lock (roles or groups named only if present): [AccessNotes] - Retool / org version notes I lock: [Version] - Workspace or team label I may quote (or UNKNOWN): [WorkspaceLabel] - App labels already present (or UNKNOWN): [AppLabels] - Permission field names already present (or UNKNOWN): [PermissionFields] - Escalation owners already present (or UNKNOWN): [Owners] - Words I must not use: [Banned] - What I must never invent (permission counts, user totals, SSO scores, or seat licenses): [Never] - Output format: [Format] - Language: [Lang] Generate: 1. Honesty ledger: AppExcerpt nouns, AccessNotes, Version, WorkspaceLabel, AppLabels, PermissionFields, Owners, Lang. Forbidden: invented permission counts, user totals, SSO scores, seat licenses. Banner: not a Retool pricing pitch; not a guaranteed compliance certification. 2. Internal app access matrix: one row per AppLabels item. Columns: app, AppExcerpt pages/resources, AccessNotes role, PermissionFields, Owners, gap. Missing Owners write NOT IN INPUTS. Use Retool Apps, Resources, Permissions, Groups, and Spaces language when AppExcerpt supports it. Never print permission-count or user-total VALUES not in AppExcerpt or AccessNotes. 3. Access lock: quote AccessNotes only. Unnamed roles stay NOT IN INPUTS. 4. Version lock: print Version. Refuse features newer than Version if Version is named. 5. Refuse list: inventing permission counts, inventing user totals, inventing SSO scores, inventing seat licenses. 6. Compliance pass: quote Banned and Never hits. Cut them. Format as Format. Constraints: - Matrix from AppExcerpt and AccessNotes only. No invented permission-count VALUES. Teach Retool access matrices, not an Appsmith or Tooljet swap. - Honor Version. No emojis.
Instructions
Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.
Generated Output
This image was generated using the prompt above.

Examples
Example Input
AppExcerpt: Harbor Quay Ops Console as pasted page Vendor Lookup as pasted resource Postgres vendors as pasted. Permission invent NONE. User invent NONE. AccessNotes: role Ops Read as pasted; Admin group UNKNOWN. Seat invent NONE. Version: Retool as pasted (do not invent unreleased AI builder pack) WorkspaceLabel: Harbor Quay Internal Tools as pasted AppLabels: Harbor Quay Ops Console as pasted; River Ops Billing UNKNOWN. PermissionFields: Ops Read as pasted. SSO score NOT IN INPUTS. Owners: platform access desk as pasted. Banned: guaranteed SOC2, permission invent, user invent, seat invent Never: invent permission counts, invent user totals, invent SSO scores, invent seat licenses Format: ledger + access matrix + access lock + version + refuse + compliance Lang: English
Example Output
1. Ledger. AppExcerpt: Harbor Quay Ops Console page Vendor Lookup resource Postgres vendors. Permission invent NONE. User invent NONE. AccessNotes role Ops Read; Admin group UNKNOWN. Seat invent NONE. Version Retool as pasted. WorkspaceLabel Harbor Quay Internal Tools. AppLabels Harbor Quay Ops Console; River Ops Billing UNKNOWN. PermissionFields Ops Read. SSO score NOT IN INPUTS. Owners platform access desk. Lang English. Banner: not a Retool pricing pitch; not a guaranteed compliance certification. Forbidden: invented permission counts, user totals, SSO scores, seat licenses. 2. Internal app access matrix. 1. Harbor Quay Ops Console | AppExcerpt Vendor Lookup + Postgres vendors | AccessNotes Ops Read | PermissionFields Ops Read | Owners platform access desk | gap: Admin group UNKNOWN | permission VALUES NONE | Retool access only. 2. River Ops Billing | AppLabels UNKNOWN | write NOT IN INPUTS | do not invent a second app. Admin group UNKNOWN so write Admin group NOT IN INPUTS. SSO score NOT IN INPUTS so write SSO VALUES NOT IN INPUTS. 3. Access lock. role Ops Read as pasted. Admin group UNKNOWN so NOT IN INPUTS. Seat invent NONE. 4. Version lock. Retool as pasted. Refuse unreleased AI builder pack. 5. Refuse list. inventing permission counts; inventing user totals; inventing SSO scores; inventing seat licenses. 6. Compliance. Quoted Banned: guaranteed SOC2, permission invent, user invent, seat invent. Cut. Quoted Never: invent permission counts, invent user totals, invent SSO scores, invent seat licenses. Cut. Format ledger + access matrix + access lock + version + refuse + compliance. Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.