When I referred to "bolt on features" I referred to features built on top of mojoPortal but that are not CMS plugin features.
There is nothing in mojoPortal that can secure some external application. You can link to some non mojoPortal page and you could set the menu page that links to it to admins only but that just hides the menu link from non admins it does not secure the external app.
"bolt on features" that are built on top of mojoPortal can leverage the internal role sytsem to enforce real security from code but some random external app or code cannot.