Design-time and runtime permissions
Access to Process Flows is controlled at two levels.
Design-time permissions control who can see and edit a process flow.
Runtime permissions control who can run and stop it.
The two are independent: a user can be allowed to run a process flow without being allowed to edit it, and the reverse.
Design-time permissions
Design-time access comes from the Cockpit role and, optionally, the development package the process flow belongs to.
- Cockpit role
-
The Process Flow Designer Cockpit function grants one of three levels: no access (None), Display, or Edit.
- No access (None)
-
Hides the Process Flow tab entirely.
- Display
-
Opens process flows read-only.
- Edit
-
Allows full changes to the Canvas, the Interface, and the Roles tab.
- Package
-
If a process flow is assigned to a development package, a user also needs permission on that development package to see or edit it. Development package permission narrows visibility further. It does not replace the Cockpit role check.
Runtime permissions
Runtime access is configured per process flow, on its Roles tab in the Process Flow Designer. Editing the Roles tab itself needs edit access to the Process Flow Designer.
- Owner
-
The user who created the process flow can always run and stop it, even when the Roles tab is empty or lists a role the owner is not part of.
- Assigned role
-
A user who is not the owner can run and stop the process flow only when they hold one of the roles assigned on the Roles tab.
If a user without runtime permission selects Run or Stop, the action is refused with an error message and nothing runs or stops.
Design-time compared with runtime
| Design time | Runtime | |
|---|---|---|
Where it is set |
Cockpit role administration, and the process flow’s development package. |
The process flow’s Roles tab. |
What it controls |
Whether the process flow is visible, and whether it can be edited. |
Whether a user can run or stop the process flow. |
Levels |
No access, display, or edit. |
Owner, assigned role, or no access. |