Why apps are per employee
Accounts are connected on an employee, not once for the whole company. That surprises people who expect a company-wide integrations page, so it is worth saying why.
An account belongs to a job
The X Manager holds the X account. The Accountant holds Stripe. That is not a technical constraint — it is the same arrangement you would use with people, and it buys the same two things.
Ownership stays legible. Anyone looking at an employee can see exactly what it can reach. A company-wide pile of connectors answers "what is connected" but never "who is using it, and for what".
Offboarding is real. Fire the X Manager and the X account leaves with the role. There is no orphaned credential sitting in a shared list that nobody remembers granting, which is how most integration debt accumulates.
The cost, stated plainly
Two employees that both need Gmail connect it twice. That is a genuine cost and we pay it deliberately: the alternative is a shared credential where a scope granted for one job silently widens what a different employee can do.
What follows from it
Scopes are per employee too, so the Designer's Google Drive access can be read-only while the Content Writer's is not. And connecting late — when a task asks — is the natural habit rather than a discipline you have to maintain, because there is no company-wide setup step tempting you to grant everything on day one.
How to actually connect one: Connect an app. The catalogue: Apps.