Skip to main content

Organization permissions

Compare Owner, Admin, and Member access to ActionFlows, Action Agents, and organization resources.

Organization permissions

ActionFlows resources belong to an organization. The custom-resource permissions below are evaluated for the organization that owns the resource; permission in one organization does not grant access to another.

Role matrix

ResourceOwner/AdminMember
ActionFlowsCreate, read, update, trigger, deleteCreate, read, update, trigger
Action AgentsCreate, read, update, trigger, review, deleteCreate, read, update, trigger, review
ArtifactsCreate, read, update, deleteCreate, read, update, delete
CredentialsCreate, read, update, deleteCreate, read
CreditsCreate, read, update, cancelRead
MCPCreate, read, update, deleteCreate, read
Prompt skillsCreate, read, update, deleteCreate, read, update
API keysCreate, read, update, deleteNo custom-resource access
WebhooksCreate, read, update, deleteNo custom-resource access

Owner and Admin have the same custom-resource permissions. The matrix does not replace the organization-management permissions provided by the underlying role system.

Organization isolation

Organization-scoped API-key requests are constrained to the key's organization. User-scoped API keys have no active organization and must request an organization the user can access. A mismatch is rejected.

Public run access is authorized against the run's owning organization, so a public run identifier cannot be used to read or operate on a run in another organization. This isolation applies to the REST API, SDK, and hosted MCP integrations.

On this page