Best Practices
A well-designed permission model helps organizations protect sensitive resources, reduce operational risk, and scale AI adoption securely.
The following best practices are recommended when managing users, roles, teams, and published AI services.
Follow the Principle of Least Privilege
Section titled “Follow the Principle of Least Privilege”Grant users only the permissions required to perform their responsibilities.
Avoid assigning elevated permissions unless they are necessary.
Recommended
- Give administrators only to platform owners.
- Assign Developer roles to AI builders.
- Use User roles for business users consuming AI services.
Use Teams to Manage Access
Section titled “Use Teams to Manage Access”Instead of assigning permissions individually, organize users into teams.
Benefits include:
- Easier permission management
- Consistent access across projects
- Simplified onboarding and offboarding
- Better collaboration
Separate Development and Production
Section titled “Separate Development and Production”Use separate workspaces for development, testing, and production environments.
This helps:
- Prevent accidental changes to production resources.
- Safely test new AI capabilities.
- Maintain a stable production environment.
Publish Only Production-Ready Resources
Section titled “Publish Only Production-Ready Resources”Only publish Agents and AI Flows that have been thoroughly tested and reviewed.
Before publishing, verify that:
- The workflow functions as expected.
- Required Skills and MCP Servers are configured.
- Models and Knowledge Bases are correctly connected.
- Appropriate approval steps are included where necessary.
Review Permissions Regularly
Section titled “Review Permissions Regularly”As teams evolve, periodically review user roles and permissions.
Regular audits help:
- Remove unnecessary access.
- Identify inactive users.
- Ensure permissions remain aligned with responsibilities.
Protect Sensitive Operations
Section titled “Protect Sensitive Operations”For workflows that perform critical or irreversible actions, require additional safeguards.
Examples include:
- Infrastructure changes
- Database modifications
- Production deployments
- Financial approvals
- File deletion
Consider using the Human Confirmation skill to require manual approval before these actions are executed.
Secure Integrations
Section titled “Secure Integrations”When connecting external systems such as databases, cloud providers, or APIs:
- Use dedicated service accounts.
- Grant only the required permissions.
- Rotate credentials regularly.
- Avoid using administrator credentials for integrations.
Keep Published Services Organized
Section titled “Keep Published Services Organized”Organize published Agents and AI Flows into meaningful Service Catalog categories.
This improves:
- Discoverability
- User experience
- Governance
- Maintenance
Monitor Platform Activity
Section titled “Monitor Platform Activity”Regularly review platform activity to understand how AI services are being used.
Monitoring helps identify:
- Frequently used services
- Failed executions
- Unused resources
- Opportunities for optimization
Summary
Section titled “Summary”A secure permission model is built on a few simple principles:
- Grant the minimum required access.
- Organize users into teams.
- Separate development from production.
- Publish only validated AI services.
- Protect sensitive workflows with approvals.
- Review permissions regularly.
