Security and Governance

Flowgear combines identity and permissions with Environment boundaries, protected Connections, scoped API Keys, revision control, audit evidence, and Workflow Logs.

Identity and access

Use Tenant, Account, Site, and Environment scopes deliberately. Assign permissions through roles and Security Groups, then add Environment-scoped permissions where Test and Production access must differ.

Credentials and invocation

Keep endpoint values and credentials in Connections. Use API Keys to scope Environment, Workflows, users, and consumer type. Rotate service tokens without replacing the entire authorization record.

Change and release control

Use Revision Management to preserve source history and Release Management to promote tested content through ordered Environments.

Evidence

Use Audit Trail for configuration and security changes, Relationships and Last Used for dependency review, and Workflow Logs for execution evidence.

Runtime-specific controls

Workflow execution, local placement, launch controls, and published interfaces have runtime-specific security considerations: