User access to Workflow Studio flows

  • 릴리스 버전: Australia
  • 업데이트 날짜 2026년 03월 12일
  • 소요 시간: 11분
  • Administrators can grant users access to Workflow Studio flows by assigning delegated development permissions or directly assigning a user role. Administrators can also specify which features and content a user can access based on user roles. Application developers can access Workflow Studio functionality through APIs for flows, subflows, and actions.

    Access by user role

    Administrators can grant access to Workflow Studio flows by directly assigning users the flow_designer user role, which includes the role to view flow execution details.

    경고:
    Directly granting a user the flow_designer role is equivalent to giving the user the admin role, because Workflow Studio can run flows as the System user, which has access to all tables and all database operations.

    Administrators can also grant users one or more Workflow Studio roles to enable them to create flows and subflows, view flow execution details, and create actions.

    표 1. Workflow Studio roles
    Role title [name] Description Contains Roles
    flow_admin Enables limited admin access to all Workflow Studio flow, subflow, and action content. flow_designer, flow_operator, flow_write_enabled, action_designer, action_category_creator, action_write_enabled, flow_designer_scripting, connection_admin, flow_report_viewer
    flow_designer Enables you to launch the Workflow Studio flow design environment to create and edit flows and subflows. flow_operator, trigger_designer
    flow_designer_scripting Enables someone with the flow_designer or action_designer role to set and modify input values by writing inline scripts. For information, see Inline scripts. none
    flow_operator Enables you to view flow execution details, dashboards, and logs. Administrators can grant this role to users that want to be able to view flow results but not create, change, or test them. none
    flow_report_viewer Enables you to view reports for Workflow Studio flow tables. For a list of relevant flow reporting tables, see Flow execution details retention. none
    trigger_designer Enables you to launch Workflow Studio and create, edit, and delete a saved trigger. none
    action_designer Enables you to launch the Workflow Studio action design environment to create and edit actions.
    중요사항:
    This role provides access to all actions regardless of their application scope.
    none
    action_category_creator Enables someone with the action_designer role to create action categories for actions and subflows. none
    fd_read Enables you to launch the Workflow Studio flow and action design environments to view the configuration and execution details of flows, subflows, and actions.
    주:
    Read only roles are incompatible with roles that provide write access. Avoid granting the same user both a read only and a write access role.
    fd_read_flows, fd_read_actions, fd_read_operations
    fd_read_flows Enables you to launch the Workflow Studio flow design environment to view the configuration and execution details of flows and subflows.
    주:
    Read only roles are incompatible with roles that provide write access. Avoid granting the same user both a read only and a write access role.
    fd_read_operations
    fd_read_actions Enables you to launch the Workflow Studio action design environment to view the configuration of actions.
    주:
    Read only roles are incompatible with roles that provide write access. Avoid granting the same user both a read only and a write access role.
    none
    fd_read_operations Enables you to view basic flow and action execution details. When reporting is enabled, you can only see basic execution details such as the runtime state and duration. If the reporting level generates additional details, you can't see them. Administrators can grant this role to users that only need to view basic execution results but not create, change, or test flows and actions.
    주:
    Read only roles are incompatible with roles that provide write access. Avoid granting the same user both a read only and a write access role.
    none
    fd_read_operations_all Enables you to view all generated flow and action execution details. When reporting is enabled, you can view all available execution details. You can only see as much detail as defined by the reporting level system property. Administrators can grant this role to users that need to view all flow results but not create, change, or test flows and actions.
    주:
    Read only roles are incompatible with roles that provide write access. Avoid granting the same user both a read only and a write access role.
    fd_read_operations
    주:
    Some applications provide UI actions to view related flow or flow contexts. You need an application-specific user role to view such UI actions. For example, users require the itil or equivalent user role to view the Flow Context UI action available from Requested Item records.

    API access

    Application developers can access Workflow Studio functionality through APIs for flows, subflows, and actions. Flow authors can enable individual flows, subflows, and actions to be client callable during design. For more information, see API access to Workflow Studio flows.

    Delegated development access

    Administrators can grant users access to Workflow Studio flows by creating an application and assigning users as developers with the delegated development permission. Delegated development allows administrators to control whether flow designers can access features normally restricted to admin users such as assigning user roles, creating access controls, or creating scripts. For more information, see Developer permissions.

    Role-based content filtering

    Specify the user roles necessary to access Workflow Studio flow content. For example, flows, flow triggers, actions, and subflows. Manage content filtering by creating content definitions and content filtering rules. For more information, see Content filtering for Workflow Studio flows.

    주:
    Your users must have the flow_designer role to create and edit flows. You can specify the additional roles that a user must have to access particular features or content.

    Role-based feature access

    Specify additional user roles necessary to access the UI elements of Workflow Studio flows. For example, specify a role to access the buttons to save, test, or activate a flow or to access the option to copy a code snippet. Manage feature access directly through the Feature Access List. For more information, see Manage access to Workflow Studio flow features.
    주:
    Your users must have the flow_designer role to create and edit flows. You can specify the additional roles that a user must have to access particular features or content.