Roles & Permissions

Control who can configure governance rules, manage connections, and access sensitive data.

Role hierarchy#

LumenFlow uses a role-based access control (RBAC) model:

RoleGovernanceConnectionsConversationsBilling
OwnerFullFullFullFull
AdminCreate/edit rulesAdd/removeView allView
MemberView rulesUse existingOwn only
ViewerView rulesView assigned

Permission details#

Governance permissions#

ActionOwnerAdminMemberViewer
Create rulesYesYes
Edit rulesYesYes
Delete rulesYes
View rulesYesYesYesYes

Connection permissions#

ActionOwnerAdminMemberViewer
Add connectionYesYes
Remove connectionYesYes
Use in SidekickYesYesYes
View connectionsYesYesYesYes

Enterprise governance overlays#

Enterprise trust adds org-scoped reviewer and admin posture on top of workspace roles. Those reviewers act on the same approval and evidence flow as the workspace, rather than through a separate enterprise-only runtime.

Best practices#

  • Use the principle of least privilege — give users the minimum access they need
  • Review role assignments quarterly
  • Separate day-to-day workspace roles from enterprise reviewer posture so sensitive approvals stay with the right audience

warning Only Owners can modify billing settings and delete the workspace. Ensure at least two people have the Owner role.