Overview
FlowX security spans five layers, each documented in its own guide:- Identity: authentication is delegated to your identity provider through a standards-based IAM integration.
- Access control: role-based access control (RBAC) governs what each user can do in the Designer, per organization, workspace, and project.
- Runtime authorization: separate, project-scoped controls decide who can access a published solution at runtime.
- Auditability: a dedicated Audit service records platform events in a centralized location.
- AI data protection: personal data is detected and redacted before it reaches a model, and AI usage maps to regulatory controls.
Identity and access management
FlowX delegates authentication to an external identity provider. Step-by-step configuration guides cover Keycloak and Microsoft Entra ID.IAM solution
The identity and access management framework FlowX uses to control access to digital identities
Configuring an IAM solution (Keycloak)
Step-by-step Keycloak setup for managing users, roles, and apps
Configuring an IAM solution (Entra ID)
Step-by-step Microsoft Entra ID setup for managing users, roles, and apps
Roles and permissions
Access in the Designer is governed by RBAC at organization, workspace, and project level.Roles and permissions matrix
Detailed permission matrices for all FlowX roles across organization, workspace, and project levels
Workspaces access rights
Workspace-level access rights and role-based access control
Runtime authorization
Project-scoped roles, end-user groups, and solution sharing for controlling runtime access to published solutions
End-user access management
Managing access for the end users of your published solutions
Audit
The Audit service provides a centralized record of platform events.Audit
The Audit service and the details captured for each audit event
Audit setup
Deploying and configuring the Audit service
AI and data protection
Personal Information Guard
Detect and redact personal data (PII) before it reaches a model, and restore it afterwards
EU AI Act
18 EU AI Act requirements mapped to Observatory controls, with scope by risk tier
Data architecture
Which data stores FlowX uses, what each stores, and how they fit together

