Skip to main content
Noxus authorization is scope-driven and split between:
  • workspace-level permissions
  • organization/global permissions

Workspace-Level Scopes

These scopes are specific to a workspace and govern what users can do inside that workspace.
CategoryScope NameLabelDescription
Flowsworkspace.flows.createCreateCreate workflows/flows
Flowsworkspace.flows.editEditEdit workflows/flows
Flowsworkspace.flows.deleteDeleteDelete workflows/flows
Flowsworkspace.flows.runRunExecute workflows/flows
Flowsworkspace.flows.advancedAdvancedAdvanced workflow operations
Agentsworkspace.agents.createCreateCreate agents
Agentsworkspace.agents.editEditEdit agents
Agentsworkspace.agents.deleteDeleteDelete agents
Agentsworkspace.agents.runRunExecute agents
Agentsworkspace.agents.advancedAdvancedAdvanced agent operations
Knowledge Basesworkspace.kbs.createCreateCreate knowledge bases
Knowledge Basesworkspace.kbs.editEditEdit knowledge bases
Knowledge Basesworkspace.kbs.deleteDeleteDelete knowledge bases
Knowledge Basesworkspace.kbs.runRunQuery knowledge bases
Knowledge Basesworkspace.kbs.advancedAdvancedAdvanced KB operations
Administrationworkspace.integrations.editEdit IntegrationsManage workspace integrations
Administrationworkspace.users.editEdit UsersManage workspace users
Administrationworkspace.users.deleteDelete UsersRemove users from workspace
Administrationworkspace.settings.editEdit SettingsModify workspace settings

Global / Organization-Level Scopes

These scopes control cross-workspace and organization-level operations.
CategoryScope NameLabelDescription
Usersusers.readReadView user information
Usersusers.writeWriteCreate users
Usersusers.editEditModify user information
Usersusers.deleteDeleteRemove users
Workspacesworkspace.readReadView workspace information
Workspacesworkspace.writeWriteCreate workspaces
Workspacesworkspace.editEditModify workspaces
Workspacesworkspace.deleteDeleteRemove workspaces
Organizationorg.readReadView organization information
Organizationorg.editEditModify organization settings
Organizationorg.billingBillingManage billing and subscriptions
Global Settingssettings.readReadView global settings
Global Settingssettings.editEditModify global settings
Global Settingssettings.adminAdminFull administrative access

Admin Configuration Tie-In

Authorization policy, role-to-scope mapping, and global controls should be managed from Noxus admin settings by users with global admin permissions.
Keep role definitions small and composable. Use scopes as the stable contract.