Connection and Knowledge Base Permissions
Restrict access to Connections and Knowledge Bases.
End-user connections (use the end user’s credentials)

Last updated
Was this helpful?
Restrict access to Connections and Knowledge Bases.
Use permissions to control who can view and use Connections and Knowledge Bases. This helps protect credentials and sensitive internal data.
Permissions here work alongside Role-Based Access Control (RBAC).
Users may be able to run a published workflow that uses a connection or Knowledge Base, even if they can’t see that resource in the Connections or Knowledge Bases list.
If a workflow uses sensitive resources, keep it in a private folder with a restricted allowlist.
Connections are private by default. Visibility depends on both the user role and the connection’s sharing settings.
This helps keep integration credentials scoped to the people who need them. It also reduces accidental reuse of sensitive connections in new workflows.
Admins: Can view and use all connections in the organization.
Editors and Users: Can view and use connections they created or that were shared with them.
Viewers: Cannot view or use connections.
Open the connection.
Update the access level (admin/edit/view), or add specific users and groups.

Put workflows that use sensitive connections in private folders.
Limit folder access to a specific group (for example, “Finance Ops”).
Prefer sharing a connection with groups over many individual users.
Knowledge Bases are private by default. Visibility depends on both the user role and the Knowledge Base’s sharing settings.
Use this to ensure sensitive content is only available to approved teams.
Admins: Can view and use all Knowledge Bases in the organization.
Editors and Users: Can view and use Knowledge Bases they created or that were shared with them.
Viewers: Cannot view or use Knowledge Bases.
Open the Knowledge Base.
Update the access level (admin/edit/view), or add specific users and groups.

Store sensitive workflows in private folders with restricted access.
Split content into separate Knowledge Bases by sensitivity or team ownership.
Prefer sharing to groups to keep access manageable over time.
For certain apps, StackAI can run a connection using the end user’s credentials. This helps ensure the workflow only returns data the end user is allowed to access.
To enable this, select Use end-user connection while building your workflow. End users will be prompted to authorize before they can run the agent.

Last updated
Was this helpful?
Was this helpful?

