Security is a shared responsibility. FlowKeyOps provides controls for managing desired state, operational metadata, and authorized actions; your team remains responsible for how accounts, integrations, and automation behavior are configured.
FlowKeyOps responsibilities
- Protect the FlowKeyOps service and its customer access boundaries.
- Apply authorized operations to the selected workspace and environment.
- Avoid displaying credential values in normal control-panel and documentation workflows.
- Provide operational status and audit context for supported actions.
Your responsibilities
- Protect user accounts, recovery channels, and connected-system credentials.
- Assign appropriate access and remove it when no longer needed.
- Review workflow logic, third-party endpoints, permissions, and data handling.
- Validate changes in a lower-risk environment before production.
- Maintain recovery procedures and comply with your legal and organizational requirements.
- Report suspected compromise promptly.
Connected services have their own controls
An automation runtime, source repository, identity provider, or third-party API may enforce separate permissions and retention rules. FlowKeyOps cannot grant permissions that the connected service has denied, and it does not replace that service’s security administration.
When responsibilities are unclear
Pause the change and ask your workspace owner or FlowKeyOps Support. Include safe identifiers and the intended outcome, but never include passwords, tokens, private keys, or complete credential payloads.