Restricting users of an org to only one Workshop module

I’ll have an org on my enrollment where only external users will log in. I’d like them to have only view-only access to one Workshop module. I want to ensure that even if they have any direct URLs, they don’t see anything else.

I see this warning on Control Panel > Application Access, but it’s unclear from the docs what the actual security feature this warning is referring to is.

I’d still like the functionality of other apps. Eg. Automate should still run in the background, but Automate should not be visible if someone has a direct Automate link.

Concepts • Classification-based Access Controls • Palantir