Skip to main content

Overview

FlowX security spans five layers, each documented in its own guide:
  1. Identity: authentication is delegated to your identity provider through a standards-based IAM integration.
  2. Access control: role-based access control (RBAC) governs what each user can do in the Designer, per organization, workspace, and project.
  3. Runtime authorization: separate, project-scoped controls decide who can access a published solution at runtime.
  4. Auditability: a dedicated Audit service records platform events in a centralized location.
  5. AI data protection: personal data is detected and redacted before it reaches a model, and AI usage maps to regulatory controls.
This page routes to the detailed documentation for each layer.

Identity and access management

FlowX delegates authentication to an external identity provider. Step-by-step configuration guides cover Keycloak and Microsoft Entra ID.

IAM solution

The identity and access management framework FlowX uses to control access to digital identities

Configuring an IAM solution (Keycloak)

Step-by-step Keycloak setup for managing users, roles, and apps

Configuring an IAM solution (Entra ID)

Step-by-step Microsoft Entra ID setup for managing users, roles, and apps

Roles and permissions

Access in the Designer is governed by RBAC at organization, workspace, and project level.

Roles and permissions matrix

Detailed permission matrices for all FlowX roles across organization, workspace, and project levels

Workspaces access rights

Workspace-level access rights and role-based access control

Runtime authorization

Project-scoped roles, end-user groups, and solution sharing for controlling runtime access to published solutions

End-user access management

Managing access for the end users of your published solutions

Audit

The Audit service provides a centralized record of platform events.

Audit

The Audit service and the details captured for each audit event

Audit setup

Deploying and configuring the Audit service

AI and data protection

Personal Information Guard

Detect and redact personal data (PII) before it reaches a model, and restore it afterwards

EU AI Act

18 EU AI Act requirements mapped to Observatory controls, with scope by risk tier

Data architecture

Which data stores FlowX uses, what each stores, and how they fit together
Last modified on September 9, 2026