Skip to main content

Control the access to your flows

Flow permissions

The next table shows what each user can do within a folder of flows. A Reader can view the flows, Operator can view and run them, Folder admin can do all the actions in this table. You can add both local users and Entra ID groups to a folder.

Allowed    Not allowed

ReaderOperatorFolder adminDescription
FlowView flow statusSee the status of all flows on the home page.
FlowResubmit/Resume flowRun actions on the flow like Resubmit/Resume/Ignore.
FlowAdd flowCreate a new flow in a folder, possibly with alerts.
FlowEdit flowEdit flow's mapping, properties, alerts.
FlowDelete flowDelete flow from a folder.
MessagesView messagesSearch for messages passing through a flow.
FolderView foldersSee all folders and their flows on the home page.
FolderEdit folderEdit folder's name and its place in the list.
FolderGrant flow permissionsEdit folder permissions to set who can use the flows in a folder.
FolderDelete folderDelete folder and all its flows and sub-folders.
System admins

A user with the System admin role can do the same things as a Folder admin on all flows in all folders. You don't need to add them to a folder first. They can use all flows in all folders in the Dashboard.

User roles

The next table shows what each user can do in the rest of the Dashboard. A user with the role Non-admin can use some parts of the Dashboard, System admin can use everything. Entra ID users get their role from their group, local users each get their own role.

Allowed    Not allowed

Non-adminSystem adminDescription
UsersView usersGo to the
Users
page to see all local and Entra ID users.
UsersAdd local userAdd a new user with a username and password.
UsersAdd Microsoft Entra ID userUse
Sign in with...
to sign in and add the user. They must be in a synced group.
UsersEdit local user roleEdit role of local users. Entra ID users get their role from their group.
UsersDelete userDelete user from the Dashboard. For Entra ID users, also remove them from their synced groups.
GroupsView groupsGo to the
Groups
page to see all synced groups.
GroupsSync groupsRun the Sync all groups action to sync all groups now.
GroupsDisable groupDisable group to stop its members from seeing the flows.
GroupsEdit group roleEdit role of a group to set what it can do in the flows.
GroupsDelete groupDelete group's flow access. If its Entra ID users are still in the Dashboard, the group syncs back in on their next sign-in.
SettingsView settingsGo to the
Profile_name
page to see the current Dashboard settings.
SettingsEdit settingsGo to the
Profile_name
page to change the Dashboard settings.
AuditsView auditsGo to the
Audits
page to see all the logs.