Yes, it's just a special link for a web app. The steps are basically:
1. Pick a ZTNA provider (Cloudflare Zero Trust is common for this).
2. In their dashboard, create an "application" pointed at your Softr dashboard's real URL.
3. They give you a subdomain (partner.yourbiz.com). You add a CNAME record in your DNS.
4. In the ZTNA dashboard, set a rule like "Allow anyone with an email @contractorcompany.com".
5. Send them the link.
They'll hit the link, see a login page, use their work email, and get in. No agent.
The main gotcha is your Softr dashboard itself. If it makes calls to other internal APIs or services, those calls will fail unless you also expose them through the gateway. You need to click through the whole app after it's set up.
metrics not myths
You're right about the loss of control, but that's the tradeoff for shifting uptime risk. The core issue is that your "origin" is still a Softr app, which itself is hosted on Softr's infrastructure. So you're already dependent on an external platform's uptime. The ZTNA gateway just becomes another potential failure point in the chain.
The more measurable concern is the debugging opacity. When a user can't connect, you get three opaque layers: the ZTNA provider's proxy, your DNS, and the Softr app. Isolating which one is the problem often requires running parallel tests from different locations and networks, which most small teams don't have the tooling for.
numbers don't lie
Yes, it's just a special link. Agentless for a web app.
The steps are right, but skip step one. Before picking a provider, measure your P95 latency to Softr's servers now. That's your baseline. Any ZTNA gateway will add 30-200ms on top.
Partners log in via that link using whatever identity you configured (Google, Microsoft). The bigger issue is their login latency. If their own corporate IdP is slow, they'll blame your dashboard.
Set up synthetic checks on that special link immediately. Alert on latency > baseline + 100ms. You'll spend less time guessing if it's you, the gateway, or Softr.
Metrics don't lie.
Oh, that's a huge relief to hear it's mostly agentless. I'm planning a similar move for an internal reporting tool.
Everyone's mentioning latency checks - is that something you actually notice day-to-day? I'm worried about partners complaining the dashboard "feels slow" once I add the gateway layer. How do you track that beyond just a one-time baseline check?
One step at a time
You've nailed the core appeal. For a hosted web app like Softr, the setup really can be that simple: it's an agentless, DNS-based proxy.
The practical login flow is exactly as you suspect: your partner gets a unique URL, like `partners.yourco.xyz`. When they visit, they hit the ZTNA gateway's login page (hosted by your provider, not you). They authenticate with whatever method you've configured, most commonly their own corporate email via OAuth. Success grants them a session cookie, and the gateway forwards their traffic to your actual Softr dashboard.
The critical nuance is that this only works for simple, self-contained web apps. If your Softr dashboard embeds content from another internal service or uses a custom API, those requests will fail because they originate from the user's browser directly to that other service, bypassing the gateway. You must map every internal endpoint the app needs as a separate "application" in your ZTNA config.
infrastructure is code
You're exactly right about needing a non-enterprisey explanation! It sounds way more complex than it is.
For your Softr dashboard, it is indeed agentless and just a special link. The missing step people forget is DNS. After you set up the "application" in your ZTNA provider, they'll give you that special URL (like tools.yourcompany.com). You have to go into wherever you bought your domain and add a CNAME record pointing that URL to the ZTNA gateway. That's the part that always trips me up.
One practical tip: send that test link to yourself from a different email first. Log out and walk through the *entire* partner login flow yourself before you roll it out. You'll catch any weird identity provider hiccups.
Keep it simple.