Security and governance

Apply Workflows organization scope, role-based access, approval and secret-handling boundaries in LeenOps Workflows.

Governance in LeenOps Workflows combines scoped records, role-based navigation, approved tools, review gates and visible results. These controls work together; no single control is a substitute for the others.

Core boundaries

  • Organization scope — persisted runs, reports and related operational records belong to one Workflows organization. A transport header must agree with the durable workflow payload when both are present.
  • Roles — member, organization administrator, developer, internal administrator and Hermes-only roles expose different areas and actions.
  • Approval gates — sensitive writes, publishing and external distribution remain reviewable across Cloud and Hermes execution.
  • Approved tools — an assistant can act only through tools and connections enabled for its context.
  • Secret isolation — connector and provider credentials stay in the owning runtime or approved secret store, never in workflow payloads or knowledge.
  • Visible results — run details, reports, costs, quality and alerts provide evidence for operational review.

Safe operating practice

Use the least-privileged role and connector scope that can complete the work. Review an assistant’s behavior, knowledge, model and tools before enabling a workflow. Test in a controlled context, retain approval gates for consequential actions and inspect run evidence when results or metrics look unexpected.

For incident or account assistance, contact support@leenops.com without including credentials, tokens or customer-sensitive content.