Tenant isolation
Data and credentials are tenant-bound with RLS and server-side ownership checks.
Feature guide
Control identity, permissions, secrets, retention, evidence, and tenant boundaries across the platform.
Complete feature description
Governance spans tenant isolation, membership, roles, object permissions, SSO, directory synchronization, API authorization, encrypted secrets, egress controls, audit logs, retention, and runtime evidence. These controls apply during execution, not only when data is displayed.
Role permissions define what a user may view, design, execute, publish, or administer. User-context credentials re-evaluate live membership and role state, so deactivation and permission changes affect subsequent requests instead of waiting for a token to expire.
Audit and lifecycle records document administrative changes and operational events. Integration call logs, workflow runs, agent traces, retention reviews, and object dependencies provide more specialized evidence for their respective surfaces.
Data and credentials are tenant-bound with RLS and server-side ownership checks.
Permissions govern design, execution, administration, APIs, MCP, and object actions.
Invitations, memberships, SSO, directory sync, role changes, and deactivation affect live authorization.
Audit events, call logs, workflow history, lifecycle events, and retention reviews preserve evidence.
What designers and operators can do in this product area.
The main operations available in Security and governance.
Security and governance actions
Bundle granular permissions into tenant roles and assign them to users.
Security and governance actions
Apply view, edit, execute, or other controls to supported assets.
Security and governance actions
Connect identity providers and synchronize user state.
Security and governance actions
Rotate OAuth secrets, revoke tokens and keys, and reconnect provider credentials.
Security and governance actions
Define duration, exact dates, review, hold, archive, and purge rules.
Security and governance actions
Review administrative changes, runtime calls, workflow events, and policy actions.
Patterns you can adapt to your own operating model.
Keep access aligned with identity lifecycle and remove runtime authorization quickly.
Control access and retain evidence through review and disposition.