Security and Governance
Flowgear combines identity and permissions with Environment boundaries, protected Connections, scoped API Keys, revision control, audit evidence, and Workflow Logs.
Identity and access
Use Tenant, Account, Site, and Environment scopes deliberately. Assign permissions through roles and Security Groups, then add Environment-scoped permissions where Test and Production access must differ.
Credentials and invocation
Keep endpoint values and credentials in Connections. Use API Keys to scope Environment, Workflows, users, and consumer type. Rotate service tokens without replacing the entire authorization record.
Change and release control
Use Revision Management to preserve source history and Release Management to promote tested content through ordered Environments.
Evidence
Use Audit Trail for configuration and security changes, Relationships and Last Used for dependency review, and Workflow Logs for execution evidence.
Runtime-specific controls
Workflow execution, local placement, launch controls, and published interfaces have runtime-specific security considerations: