Users and permissions

AilaFlow permissions determine which processes a user can access and which people receive tasks or notifications.

Users and properties

Every user has a unique name, such as @robert. Users can also have key-value properties:

team: finance
access_level: c3

Properties let one rule target a changing group without listing every user.

User expressions

Reference a specific user:

@robert

Match users by properties:

@{.team = "finance" and .access_level = "c3"}

Combine alternatives with or:

@robert or @aila or @{.team = "finance" and .access_level = "c3"}

Rules:

  • Use and between conditions inside @{...}.
  • Use or between alternative users or groups.
  • Validate dynamic expressions before using them in a form.

Process access

Administrators decide which users or property-based groups can access a process. Access controls whether a user can:

  • See and start the process
  • Ask the user assistant to run it
  • Use it through its start form
  • Call it from another permitted process

The user assistant only considers processes available to the current user.

Tasks and notifications

Task and Notification steps use user expressions to resolve recipients.

  • A Task pauses and waits according to its completion mode.
  • A Notification sends a persistent message and continues.
  • Each task recipient receives the same task definition.

Human control

Keep sensitive decisions, approvals, and operations human-only when required. Use a Task step to pause execution and collect explicit input from an authorized user.

AI agents and user assistants operate within configured process access. They do not bypass permissions.