Control the access to your flows
Flow permissions
The next table shows what each user can do within a folder of flows. A Reader can view the flows, Operator can view and run them, Folder admin can do all the actions in this table. You can add both local users and Entra ID groups to a folder.
Allowed Not allowed
| Reader | Operator | Folder admin | Description | ||
|---|---|---|---|---|---|
| Flow | View flow status | See the status of all flows on the home page. | |||
| Resubmit/Resume flow | Run actions on the flow like Resubmit/Resume/Ignore. | ||||
| Add flow | Create a new flow in a folder, possibly with alerts. | ||||
| Edit flow | Edit flow's mapping, properties, alerts. | ||||
| Delete flow | Delete flow from a folder. | ||||
| Messages | View messages | Search for messages passing through a flow. | |||
| Folder | View folders | See all folders and their flows on the home page. | |||
| Edit folder | Edit folder's name and its place in the list. | ||||
| Grant flow permissions | Edit folder permissions to set who can use the flows in a folder. | ||||
| Delete folder | Delete folder and all its flows and sub-folders. |
A user with the System admin role can do the same things as a Folder admin on all flows in all folders. You don't need to add them to a folder first. They can use all flows in all folders in the Dashboard.
User roles
The next table shows what each user can do in the rest of the Dashboard. A user with the role Non-admin can use some parts of the Dashboard, System admin can use everything. Entra ID users get their role from their group, local users each get their own role.
Allowed Not allowed
| Non-admin | System admin | Description | ||
|---|---|---|---|---|
| Users | View users | Go to the Users page to see all local and Entra ID users. | ||
| Add local user | Add a new user with a username and password. | |||
| Add Microsoft Entra ID user | Use Sign in with... to sign in and add the user. They must be in a synced group. | |||
| Edit local user role | Edit role of local users. Entra ID users get their role from their group. | |||
| Delete user | Delete user from the Dashboard. For Entra ID users, also remove them from their synced groups. | |||
| Groups | View groups | Go to the Groups page to see all synced groups. | ||
| Sync groups | Run the Sync all groups action to sync all groups now. | |||
| Disable group | Disable group to stop its members from seeing the flows. | |||
| Edit group role | Edit role of a group to set what it can do in the flows. | |||
| Delete group | Delete group's flow access. If its Entra ID users are still in the Dashboard, the group syncs back in on their next sign-in. | |||
| Settings | View settings | Go to the Profile_name page to see the current Dashboard settings. | ||
| Edit settings | Go to the Profile_name page to change the Dashboard settings. | |||
| Audits | View audits | Go to the Audits page to see all the logs. |