Organization permissions
Compare Owner, Admin, and Member access to ActionFlows, Action Agents, and organization resources.
Organization permissions
ActionFlows resources belong to an organization. The custom-resource permissions below are evaluated for the organization that owns the resource; permission in one organization does not grant access to another.
Role matrix
| Resource | Owner/Admin | Member |
|---|---|---|
| ActionFlows | Create, read, update, trigger, delete | Create, read, update, trigger |
| Action Agents | Create, read, update, trigger, review, delete | Create, read, update, trigger, review |
| Artifacts | Create, read, update, delete | Create, read, update, delete |
| Credentials | Create, read, update, delete | Create, read |
| Credits | Create, read, update, cancel | Read |
| MCP | Create, read, update, delete | Create, read |
| Prompt skills | Create, read, update, delete | Create, read, update |
| API keys | Create, read, update, delete | No custom-resource access |
| Webhooks | Create, read, update, delete | No custom-resource access |
Owner and Admin have the same custom-resource permissions. The matrix does not replace the organization-management permissions provided by the underlying role system.
Organization isolation
Organization-scoped API-key requests are constrained to the key's organization. User-scoped API keys have no active organization and must request an organization the user can access. A mismatch is rejected.
Public run access is authorized against the run's owning organization, so a public run identifier cannot be used to read or operate on a run in another organization. This isolation applies to the REST API, SDK, and hosted MCP integrations.
Related
Credential Management
Named ActionFlows organization connections, runtime secret resolution, permissions, and current public-history redaction behavior.
AI Model Selection Guide
Choose the right AI model for every ActionFlows node. Compare providers, models, capabilities, and cost trade-offs to balance quality, speed, and budget.