Skip to content

Permissions ​

Endpoints require permissions. A person or key gets permissions from its roles: exactly one base role, plus any number of duty roles.

Permissions ​

PermissionAllows
records.readSee records in the apps they can open
records.writeCreate and change records
apps.configureConfigure apps (document types, checks, policies)
processes.readSee processes and runs
processes.runStart and cancel process runs
processes.editInstall, edit and turn processes on or off
processes.promoteRaise a process's autonomy or its automated share
tasks.workWork on assigned tasks
approvals.decideApprove or reject AI actions
connections.manageConnect mailboxes and other apps
billing.manageBilling settings, products, voiding and marking invoices paid
payments.refundRefund payments
members.readSee who is in the workspace
members.manageInvite, suspend and remove people
roles.grantChange people's roles and app access
security.manageSecurity settings, single sign-on, sessions
api_keys.manageCreate and revoke API keys
audit.readRead and export the audit log
changes.approveApprove other people's changes (four-eyes)
workspace.manageRename the workspace
workspace.transferGrant or remove the owner role
usecases.readBrowse the use-case catalog and the workspace's use cases
usecases.manageSet the workspace's tags, take up use cases, set their status and owner

Roles ​

RoleKindPermissions
Ownerbaseall
Adminbaseall except workspace.transfer
Memberbaserecords.read, records.write, processes.read, processes.run, tasks.work, members.read, usecases.read
Viewerbaserecords.read, processes.read, members.read, usecases.read
Guestbaserecords.read, records.write, tasks.work — only in the apps they're given
Approverdutyapprovals.decide
Financedutybilling.manage, payments.refund, approvals.decide
Process ownerdutyprocesses.edit, processes.run, apps.configure, usecases.read, usecases.manage
Risk officerdutychanges.approve, processes.promote, approvals.decide, audit.read
Auditordutyaudit.read, records.read, processes.read, members.read, usecases.read

API keys may hold viewer, member, process_owner, finance and approver — never owner, admin or risk officer.

App routes ​

Inside an app's API (for example /v1/crm/…), reading (GET) needs records.read and anything else needs records.write, on top of the app being enabled for the workspace and allowed for the token.

Separation of duties ​

Some rules hold whatever the permissions:

  • Nobody can approve their own change.
  • Whoever built the current version of a process can't approve raising its autonomy or automated share.
  • With four-eyes on, changes that widen what can happen without a person (more automation, looser controls, new privileged roles, turning on an API key) wait for a second person. The API answers 202 Accepted with the pending change request. Narrowing changes apply at once.

NeodyAI — run your business from one place.