FlowSharp clearly separates who designs, who operates, who administers and who observes. The 5 roles are cumulative in permissions (Admin includes everything Operator can do).
| Role | What they can do |
|---|---|
| ReadOnly | Views flows, items, tasks, dashboards and documentation without modifying anything. Ideal for stakeholders, auditors or managers who want visibility without operability. |
| Operator | Manages items, completes tasks, executes transitions, updates operational data. This is the daily work role: advancing cases, filling forms, uploading documents. |
| FlowDesigner | Creates and modifies flows, Process Maps, rules, tasks, process configurations. Designs and publishes operational flows. Does not manage users or tenant settings. |
| Admin | Everything FlowDesigner can do, plus: user and role management, settings, AI providers, integrations, API keys, global variables and tenant configurations. |
| Super Admin | Manages tenants, impersonation, plans, demo data and multi-tenant aspects. Reserved for the FlowSharp team for support and platform management. |
Best practices:
- Assign ReadOnly to managers who want visibility without risk of accidental changes
- Keep FlowDesigner separate from Admin to avoid having process designers also manage access
- Review roles periodically with the access audit available in Analytics
