Security and governance
Apply Workflows organization scope, role-based access, approval and secret-handling boundaries in LeenOps Workflows.
Governance in LeenOps Workflows combines scoped records, role-based navigation, approved tools, review gates and visible results. These controls work together; no single control is a substitute for the others.
Core boundaries
- Organization scope — persisted runs, reports and related operational records belong to one Workflows organization. A transport header must agree with the durable workflow payload when both are present.
- Roles — member, organization administrator, developer, internal administrator and Hermes-only roles expose different areas and actions.
- Approval gates — sensitive writes, publishing and external distribution remain reviewable across Cloud and Hermes execution.
- Approved tools — an assistant can act only through tools and connections enabled for its context.
- Secret isolation — connector and provider credentials stay in the owning runtime or approved secret store, never in workflow payloads or knowledge.
- Visible results — run details, reports, costs, quality and alerts provide evidence for operational review.
Safe operating practice
Use the least-privileged role and connector scope that can complete the work. Review an assistant’s behavior, knowledge, model and tools before enabling a workflow. Test in a controlled context, retain approval gates for consequential actions and inspect run evidence when results or metrics look unexpected.
For incident or account assistance, contact support@leenops.com without including credentials, tokens or customer-sensitive content.

