Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Configure enterprise role-based access control for Lindy AI workspaces. Use when setting up team permissions, managing workspace access, or implementing enterprise security policies with SSO/SCIM. Trigger with phrases like "lindy permissions", "lindy RBAC", "lindy access control", "lindy enterprise security", "lindy SSO".
.claude/skills/jeremylongshore-lindy-enterprise-rbac/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 27% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 37% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 28% | 0% |
| case-05 | ✗→✓ | ▲ Improved | 53% | 0% |
| case-11 | ✗→✓ | ▲ Improved | -13% | 0% |
Lindy organizes access around workspaces where agents live. Team members are assigned roles that control who can create, modify, run, or observe agents and their execution history. Enterprise features add SSO, SCIM, audit logs, and granular permission controls.
| Role | Create Agents | Edit Agents | Run Agents | View Tasks | Manage Team | |------|:------------:|:-----------:|:----------:|:----------:|:-----------:| | Owner | Yes | Yes | Yes | Yes | Yes | | Editor | Yes | Yes | Yes | Yes | No | | Viewer | No | No | No | Yes | No |
| Org Role | Lindy Role | Rationale | |---------|-----------|-----------| | Engineering Lead | Owner | Full workspace control | | Developer | Editor | Build and modify agents | | Ops/Support | Editor | Run agents and configure workflows | | Manager | Viewer | Monitor task execution and metrics | | Stakeholder | Viewer | Read-only access to results |
Pro plan: Each additional seat costs $19.99/month Enterprise plan: Custom pricing with bulk seat discounts
Use folders to organize agents by team, function, or environment:
Workspace: Acme Corp Production
├── Support/
│ ├── Email Triage Agent
│ ├── FAQ Chatbot
│ └── Escalation Agent
├── Sales/
│ ├── Lead Router
│ ├── Follow-up Agent
│ └── Meeting Scheduler
├── Operations/
│ ├── Daily Report Agent
│ ├── Monitoring Agent
│ └── Data Pipeline Agent
└── Shared/
├── Knowledge Base Agent
└── Notification AgentFolder permissions: Share folders with specific team members to control visibility. Agents in private folders are only visible to the folder owner.
Each agent can be shared independently:
| Sharing Level | Who Gets It | What They Can Do | |--------------|-------------|-----------------| | Edit access | Team collaborators | Edit agent, see all tasks | | User access | Agent consumers | Run agent, trigger workflows | | Template | Anyone with link | Make a copy (no access to original) |
Control which team members can use shared integration connections:
Create separate API keys per integration purpose:
| API Key | Purpose | Scope | Rotation | |---------|---------|-------|----------| | lnd_prod_app_xxxx | Application webhook triggers | Production only | 90 days | | lnd_prod_ci_xxxx | CI/CD smoke tests | Test agents only | 90 days | | lnd_prod_monitor_xxxx | Monitoring/observability | Read-only | 90 days |
Revoke keys immediately when a team member with access leaves the organization.
SSO (Single Sign-On):
SCIM (User Provisioning):
Audit Logs:
Encryption:
When a team member leaves:
| Issue | Cause | Solution | |-------|-------|----------| | 403 Forbidden on agent create | User has Viewer role | Promote to Editor | | Agent not visible to teammate | Agent in private folder | Move to shared folder | | API key returns 401 | Key revoked or expired | Generate new key | | Cannot delete workspace | Not the Owner | Transfer ownership first | | SSO login fails | SAML misconfigured | Verify IdP metadata and assertions | | SCIM not syncing | Endpoint URL wrong | Check SCIM endpoint in IdP config |
Proceed to lindy-migration-deep-dive for platform migration strategies.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-12 | pass→pass | 17,669 | 11,768 | -33% | 1 | 1 | 0% | 2,029 | 2,297 | +13% | 0 | 0 | — |
case-01 | fail→pass | 24,982 | 17,521 | -30% | 1 | 1 | 0% | 2,673 | 3,384 | +27% | 0 | 0 | — |
case-02 | fail→pass | 24,425 | 20,767 | -15% | 1 | 1 | 0% | 2,814 | 3,852 | +37% | 0 | 0 | — |
case-03 | fail→pass | 18,641 | 18,453 | -1% | 1 | 1 | 0% | 2,596 | 3,334 | +28% | 0 | 0 | — |
case-04 | fail→fail | 31,991 | 31,776 | -1% | 1 | 1 | 0% | 4,754 | 6,664 | +40% | 0 | 0 | — |
case-05 | fail→pass | 24,497 | 22,883 | -7% | 1 | 1 | 0% | 2,632 | 4,033 | +53% | 0 | 0 | — |
case-06 | fail→fail | 18,397 | 14,758 | -20% | 1 | 1 | 0% | 2,221 | 2,687 | +21% | 0 | 0 | — |
case-07 | fail→fail | 12,271 | 9,994 | -19% | 1 | 1 | 0% | 886 | 2,104 | +137% | 0 | 0 | — |
case-08 | pass→pass | 12,272 | 10,504 | -14% | 1 | 1 | 0% | 1,045 | 2,057 | +97% | 0 | 0 | — |
case-09 | pass→pass | 15,809 | 8,361 | -47% | 1 | 1 | 0% | 1,744 | 1,966 | +13% | 0 | 0 | — |
case-10 | pass→pass | 21,936 | 15,061 | -31% | 1 | 1 | 0% | 2,144 | 3,055 | +42% | 0 | 0 | — |
case-11 | fail→pass | 23,374 | 9,182 | -61% | 1 | 1 | 0% | 2,444 | 2,126 | -13% | 0 | 0 | — |
case-13 | pass→pass | 19,215 | 19,233 | +0% | 1 | 1 | 0% | 2,319 | 3,938 | +70% | 0 | 0 | — |
case-14 | pass→pass | 16,130 | 12,227 | -24% | 1 | 1 | 0% | 2,547 | 3,437 | +35% | 0 | 0 | — |
case-15 | pass→pass | 13,110 | 8,230 | -37% | 1 | 1 | 0% | 2,128 | 2,699 | +27% | 0 | 0 | — |
case-16 | pass→pass | 13,331 | 4,377 | -67% | 1 | 1 | 0% | 1,183 | 2,158 | +82% | 0 | 0 | — |
case-17 | pass→pass | 17,652 | 9,164 | -48% | 1 | 1 | 0% | 2,166 | 2,583 | +19% | 0 | 0 | — |
case-18 | fail→pass | 12,641 | 8,156 | -35% | 1 | 1 | 0% | 2,115 | 1,710 | -19% | 0 | 0 | — |
case-19 | pass→pass | 10,673 | 8,012 | -25% | 1 | 1 | 0% | 896 | 1,859 | +107% | 0 | 0 | — |
case-20 | pass→pass | 7,778 | 9,698 | +25% | 1 | 1 | 0% | 1,239 | 2,129 | +72% | 0 | 0 | — |
case-21 | fail→pass | 10,380 | 3,153 | -70% | 1 | 1 | 0% | 1,681 | 1,951 | +16% | 0 | 0 | — |
case-22 | fail→pass | 16,140 | 5,166 | -68% | 1 | 1 | 0% | 2,279 | 2,216 | -3% | 0 | 0 | — |
case-23 | pass→pass | 14,940 | 7,504 | -50% | 1 | 1 | 0% | 1,214 | 1,816 | +50% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +35 percentage points is the difference between those two pass rates over the 23 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.