Improve Traceability and Productivity working with boards
Stop opening five tabs to see what's blocking what. Cross-Board Tree shows every board, item, subitem, and cross-board dependency as a single interactive tree — all the relationships your team works with, in one place.
Cross-Board Tree is a Board View that turns the relationships between your monday boards into a single interactive tree.
WHAT IT DOES
Starting from any board, the tree expands upward to its folder and workspace, and downward through items, subitems, and any cross-board connection defined by board_relation or dependency columns. Each node displays live monday data: status colors, due dates, assignees, timeline, time tracking, and group. Click an item to open its native monday panel.
- Cross-board relations through board_relation and dependency columns
- Automatic cycle detection — never get lost in circular dependencies
- Filters by status, assignee, tags, board, group, type and link direction
- Search by name or ID with auto-expand of matching ancestors
- Save the visual state of the tree for the entire workspace
- Export the visible tree to Excel — two sheets (Elements + Relations)
- Configurable column resolution when boards have multiple status/people/date columns
WHO IT'S FOR
Project managers, PMOs, consultants, and teams running interconnected projects across 5+ boards who need a single source of truth for their multi-board workflows.
Security & Compliance
Security
Does the developer periodically perform penetration testing?
No
Does the developer have a dedicated security and privacy point of contact for such issues or questions?
Yes
contact@support.com
Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?
Yes
The application performs no browser redirects or forwards to external destinations. Its only navigation action opens a monday.com item card through the official monday SDK, using an internal item identifier rather than a URL. Any links the app generates point exclusively to the customer's own monday.com account domain, so there are no untrusted redirect destinations.
Does the app protect against mass parameter assignment attacks?
Yes
The application is a fully client-side monday.com board view with no backend or server-side endpoints of its own, so there is no request-to-model binding that a mass assignment attack could target. All data access is performed through monday.com's official API, which enforces field-level permissions and validation on its side.
Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?
Yes
The application is built with React, which automatically encodes all displayed values as safe text before rendering them, so data coming from monday.com (such as item names and column values) can never be interpreted as executable markup. The app uses no mechanism that would bypass this automatic output encoding, providing consistent protection against Cross-Site Scripting.
Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?
Yes
The application has no backend or authenticated endpoints of its own. Every state-changing action — such as saving the view's state or reading board data — is performed through the monday SDK and API, which authenticate using monday's session token rather than ambient browser cookies. Because there is no cookie-authenticated endpoint on our side, there is no surface exposed to Cross-Site Request Forgery; the monday.com platform handles CSRF protection for its API.
Does the developer have mechanisms to notify monday.com in case of a security breach?
Yes
We have defined the security procedure in case of a breach and will be certified for ISO 27001 by early November 2026
Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?
Yes
The application's software dependencies are continuously monitored for known vulnerabilities through automated scanning and audit tooling, and security patches are applied promptly, after which the app is rebuilt and redeployed. The app runs fully client-side and maintains no database or backend service of its own, so there is no server or database infrastructure requiring separate patching; all data storage is handled by the monday.com platform.
Compliance
Is the app certified with the information security standard ISO/IEC 27001:2022?
No
Not yet. Scheduled for Nov 2026
Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?
No
Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?
No
Is the app compliant with the General Data Protection Regulation (GDPR)?
Yes
The app is designed in line with GDPR principles. It runs fully client-side with no backend or database of its own: it collects no personal data independently, persists only its own technical view state within monday.com's platform storage, and sends no data to any third party outside monday.com. Any personal data displayed originates from and remains within the customer's monday.com account, where monday.com acts as the data processor under its data processing terms. Our processing practices are covered by our privacy policy.
Data
Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).
No
The application does not send any data to destinations outside monday.com. All communication takes place through the official monday SDK and API — reading board data and storing the app's own view state — and the only analytics used is monday's built-in engagement signal, which stays within the monday platform and carries no customer data. Client-side features such as Excel export generate the file locally in the user's browser and transmit nothing externally
Where does the app store logs data?
other
The app does not store logs. Logging is ephemeral and limited to the end user's own browser console; no log data is persisted in monday storage, on AWS, or on any infrastructure of ours, and nothing is transmitted to an external logging service.
Where does the app store the app data?
monday
The app stores all of its data in monday.com's own storage. Application state — such as the saved view state and user configuration — is persisted through the monday SDK's instance storage, scoped per board. The app maintains no database or backend of its own and stores no data on any external infrastructure.
Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?
Yes
The application never logs secrets: it does not handle raw API tokens or credentials at all — authentication is managed entirely by the monday SDK — so none can appear in logs. Production logging is limited to technical status and error diagnostics (operation identifiers and API error conditions) and never includes personal content. The codebase is continuously analyzed by Aikido, whose secret detection would flag any credential before release. No logs are persisted or transmitted anywhere.
Is customer data segregated from the data of other customers (for example logically or physically)?
Yes
The app operates no database or backend of its own, so it never stores multiple customers' data together in shared infrastructure. The only data the app persists is its own state, which is written to monday.com's per-instance storage — isolated per board and account by the platform — and the app additionally validates that any stored state belongs to the current account and board before using it. All broader customer data resides within monday.com, which enforces tenant-level segregation.
Privacy
Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?
Yes
Multi-factor authentication is enforced across the tools and accounts our team uses, and credentials are managed centrally through a dedicated password manager (Bitwarden). The app itself is fully client-side with no backend or database of its own, so customer data is processed within the monday.com platform rather than on infrastructure we operate.
Does the developer protect access to customer data based on the principle of least privilege?
Yes
The application requests only the minimum monday.com permissions required to function: it reads board structure and items to render the view and stores its own view state in the app's dedicated storage. It performs no writes to or modification of customer board data. The app operates no backend or database of its own — customer data is processed within the monday.com platform.
Reviews
No reviews yet.
Historical data
Installation history
We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.
Total number of installs
Change in total number of installs in last 1 day(s)
Compares the number of installs on each date with 1 days previously:
Max
Min
Current
Change in total number of installs in last 7 day(s)
Compares the number of installs on each date with 7 days previously:
Max
Min
Current
Change in total number of installs in last 30 day(s)
Compares the number of installs on each date with 30 days previously:
Max
Min
Current
Change in total number of installs in last 90 day(s)
Compares the number of installs on each date with 90 days previously:
Max
Min
Current
Change in total number of installs in last 180 day(s)
Compares the number of installs on each date with 180 days previously:
Max
Min
Current
Ratings history
Categories history
Each of the following is a yes/no answer, so the graphs show 1 for yes, and 0 for no.
{
"id": 10001206,
"marketplace_developer_id": 100000230,
"app_id": 11213497,
"app_type": "app",
"security_info": {},
"gallery_assets": [
{
"url": "https://cdn.monday.com/marketplace/10001206/10001206_2026_5_7_7_8_27_g74kpjs.png",
"type": "image"
},
{
"url": "https://cdn.monday.com/marketplace/10001206/10001206_2026_5_7_7_8_31_ol7w3fg.png",
"type": "image"
},
{
"url": "https://cdn.monday.com/marketplace/10001206/10001206_2026_5_7_7_8_40_bu7yrsm.png",
"type": "image"
},
{
"url": "https://cdn.monday.com/marketplace/10001206/10001206_2026_5_7_7_8_43_jyasrobh.png",
"type": "image"
},
{
"url": "https://cdn.monday.com/marketplace/10001206/10001206_2026_5_7_7_8_47_cwct65b.png",
"type": "image"
}
],
"description": "<p>Stop opening five tabs to see what's blocking what. Cross-Board Tree shows every board, item, subitem, and cross-board dependency as a single interactive tree — all the relationships your team works with, in one place.</p><p>Cross-Board Tree is a Board View that turns the relationships between your monday boards into a single interactive tree.</p><p>WHAT IT DOES</p><p>Starting from any board, the tree expands upward to its folder and workspace, and downward through items, subitems, and any cross-board connection defined by board_relation or dependency columns. Each node displays live monday data: status colors, due dates, assignees, timeline, time tracking, and group. Click an item to open its native monday panel.</p><p>KEY FEATURES</p><p>- Hierarchical visualization: Workspace -> Folder -> Board -> Items -> Subitems</p><p>- Cross-board relations through board_relation and dependency columns</p><p>- Automatic cycle detection — never get lost in circular dependencies</p><p>- Filters by status, assignee, tags, board, group, type and link direction</p><p>- Search by name or ID with auto-expand of matching ancestors</p><p>- Save the visual state of the tree for the entire workspace</p><p>- Export the visible tree to Excel — two sheets (Elements + Relations)</p><p>- Configurable column resolution when boards have multiple status/people/date columns</p><p>WHO IT'S FOR</p><p>Project managers, PMOs, consultants, and teams running interconnected projects across 5+ boards who need a single source of truth for their multi-board workflows.</p>",
"short_description": "Improve Traceability and Productivity working with boards",
"thumbnail_url": "https://cdn.monday.com/marketplace/10001206/10001206_2026_5_7_7_8_14_516jb1f.png",
"logo_url": "https://cdn.monday.com/marketplace/10001206/10001206_2026_5_7_7_8_11_mal06tl.png",
"feedback_url": "contact@kintosoft.com",
"privacy_policy_url": "https://cbt-privacy.kintosoft.com",
"featured": false,
"name": "Cross-Board Tree",
"how_to_use_url": "https://kintosoft.gitbook.io/cross-board-tree",
"external_pricing_url": null,
"keywords": "management,excel,compliance,traceability,visualization,relationships,dependency,hierarchy,tree,board ",
"compliance_answers": [
{
"questionId": 20,
"shortAnswer": false,
"detailedAnswer": "Not yet. Scheduled for Nov 2026"
},
{
"questionId": 19,
"shortAnswer": false,
"detailedAnswer": "The application does not send any data to destinations outside monday.com. All communication takes place through the official monday SDK\nand API — reading board data and storing the app's own view state — and the only analytics used is monday's built-in engagement signal,\nwhich stays within the monday platform and carries no customer data. Client-side features such as Excel export generate the file locally\nin the user's browser and transmit nothing externally"
},
{
"questionId": 18,
"detailedAnswer": "The app does not store logs. Logging is ephemeral and limited to the end user's own browser console; no log data is persisted in monday\nstorage, on AWS, or on any infrastructure of ours, and nothing is transmitted to an external logging service.",
"logHostingProvider": "other"
},
{
"questionId": 17,
"detailedAnswer": "The app stores all of its data in monday.com's own storage. Application state — such as the saved view state and user configuration — is persisted\nthrough the monday SDK's instance storage, scoped per board. The app maintains no database or backend of its own and stores no data\non any external infrastructure.",
"dataHostingProvider": "monday"
},
{
"questionId": 15,
"shortAnswer": false,
"detailedAnswer": ""
},
{
"questionId": 14,
"shortAnswer": true,
"detailedAnswer": "contact@support.com"
},
{
"questionId": 13,
"shortAnswer": false,
"detailedAnswer": ""
},
{
"questionId": 12,
"shortAnswer": false,
"detailedAnswer": ""
},
{
"questionId": 11,
"shortAnswer": true,
"detailedAnswer": "The app is designed in line with GDPR principles. It runs fully client-side with no backend or database of\n its own: it collects no personal data independently, persists only its own technical view state within\n monday.com's platform storage, and sends no data to any third party outside monday.com. Any personal\n data displayed originates from and remains within the customer's monday.com account, where monday.com\n acts as the data processor under its data processing terms. Our processing practices are covered by\n our privacy policy."
},
{
"questionId": 10,
"shortAnswer": true,
"detailedAnswer": "The application performs no browser redirects or forwards to external destinations. Its only navigation action opens a monday.com item\ncard through the official monday SDK, using an internal item identifier rather than a URL. Any links the app generates point exclusively\nto the customer's own monday.com account domain, so there are no untrusted redirect destinations."
},
{
"questionId": 9,
"shortAnswer": true,
"detailedAnswer": "The application is a fully client-side monday.com board view with no backend or server-side endpoints of its own, so there is no request-to-model\nbinding that a mass assignment attack could target. All data access is performed through monday.com's official API, which enforces field-level\npermissions and validation on its side."
},
{
"questionId": 8,
"shortAnswer": true,
"detailedAnswer": "The application never logs secrets: it does not handle raw API tokens or credentials at all — authentication is managed entirely by the\nmonday SDK — so none can appear in logs. Production logging is limited to technical status and error diagnostics (operation identifiers and\nAPI error conditions) and never includes personal content. The codebase is continuously analyzed by Aikido, whose secret detection would flag any credential before release. No logs are persisted or transmitted anywhere."
},
{
"questionId": 7,
"shortAnswer": true,
"detailedAnswer": "Multi-factor authentication is enforced across the tools and accounts our team uses, and credentials are managed centrally through a\ndedicated password manager (Bitwarden). The app itself is fully client-side with no backend or database of its own, so customer data is processed within the monday.com platform rather than on infrastructure we operate."
},
{
"questionId": 6,
"shortAnswer": true,
"detailedAnswer": "The application requests only the minimum monday.com permissions required to function: it reads board structure and items to render\nthe view and stores its own view state in the app's dedicated storage. It performs no writes to or modification of customer board data.\nThe app operates no backend or database of its own — customer data is processed within the monday.com platform.\n"
},
{
"questionId": 5,
"shortAnswer": true,
"detailedAnswer": "The application is built with React, which automatically encodes all displayed values as safe text before rendering them, so data coming from\nmonday.com (such as item names and column values) can never be interpreted as executable markup. The app uses no mechanism that would bypass this\nautomatic output encoding, providing consistent protection against Cross-Site Scripting."
},
{
"questionId": 4,
"shortAnswer": true,
"detailedAnswer": "The application has no backend or authenticated endpoints of its own. Every state-changing action — such as saving the view's state or\nreading board data — is performed through the monday SDK and API, which authenticate using monday's session token rather than ambient\nbrowser cookies. Because there is no cookie-authenticated endpoint on our side, there is no surface exposed to Cross-Site Request Forgery;\nthe monday.com platform handles CSRF protection for its API."
},
{
"questionId": 3,
"shortAnswer": true,
"detailedAnswer": "We have defined the security procedure in case of a breach and will be certified for ISO 27001 by early November 2026"
},
{
"questionId": 2,
"shortAnswer": true,
"detailedAnswer": "The application's software dependencies are continuously monitored for known vulnerabilities through automated scanning and audit tooling,\nand security patches are applied promptly, after which the app is rebuilt and redeployed. The app runs fully client-side and maintains no\ndatabase or backend service of its own, so there is no server or database infrastructure requiring separate patching; all data storage is\nhandled by the monday.com platform."
},
{
"questionId": 1,
"shortAnswer": true,
"detailedAnswer": "The app operates no database or backend of its own, so it never stores multiple customers' data together in shared infrastructure.\nThe only data the app persists is its own state, which is written to monday.com's per-instance storage — isolated per board and account\nby the platform — and the app additionally validates that any stored state belongs to the current account and board before using it.\nAll broader customer data resides within monday.com, which enforces tenant-level segregation."
}
],
"created_at": "2026-06-07T07:07:42.000Z",
"updated_at": "2026-07-23T14:34:05.000Z",
"automation_app_id": null,
"marketplace_category_ids": [],
"pinned_for_categories_ids": [],
"featured_for_categories_ids": [],
"pricing_data": null,
"label": null,
"app_values": [
"Built for scalability"
],
"security": true,
"display_in_template_store": false,
"acquisition_source": "No touch",
"is_connector": false,
"show_connections": null,
"terms_of_service_url": "https://cbt-terms.kintosoft.com",
"available_for_tiers": [],
"available_for_products": [],
"google_analytics_tag_id": null,
"is_solution": false,
"cta_override": null,
"app_scope_str": "boards:read,workspaces:read,users:read,tags:read,teams:read,account:read",
"app_client_id": "dad57820901fcaa37dedf0c4189bb1eb",
"app_color": "#333C76",
"plans": null,
"app_live_version": {
"updated_at": "2026-07-21T08:45:31.787Z",
"id": 16236154
},
"pricing_model": null,
"monetization": {
"monetizationType": "none",
"hasFreePlan": false,
"hasPaidPlan": false,
"hasTrialPlan": false
},
"badges_data": {
"security": true,
"app_values": [
"Built for scalability"
],
"acquisition_source": "No touch",
"display_in_template_store": false
},
"data": {
"is_solution": false,
"cta_override": null,
"is_connector": false,
"available_for_tiers": [],
"terms_of_service_url": "https://cbt-terms.kintosoft.com",
"available_for_products": [],
"google_analytics_tag_id": null
},
"display": null,
"installsDelta": {
"totalInstalls": 3,
"sevenDays": 0,
"thirtyDays": 0,
"ninetyDays": -1
}
}