Data-Oriented Features

Granular control over every resource.

Vynflow secures every case, table, insight, file and context with fine-grained access levels, role-based permissions and fully isolated multi-tenant domains — so the right people see exactly what they should, and nothing they shouldn't.

Access control on every resource

Permissions are first-class across the whole platform. Grant View, Modify or Admin on the resources that matter, and tighten or loosen access without touching your data.

Resource access levels

Assign View, Modify or Admin access on cases, tables, insights, files and contexts — granular control on each resource, not just all-or-nothing.

IAM & role-based access

Build custom roles with tailored permissions across resources, then assign them to members. Available on Organization plans.

Multi-tenant domains

Each domain is an isolated workspace with its own cases, tables, users and config. Manage members and invites, and switch domains in a click.

Two-factor authentication

Protect accounts with TOTP or email-based 2FA, recovery codes for safe fallback, and per-domain enforcement to require it across a workspace.

Session management

DB-backed sessions let users view active sessions, revoke one or all others, and re-verify on IP change — backed by a full activity log.

Service accounts & API keys

Issue scoped API credentials for server-to-server integration, kept separate from human accounts and governed by the same access model.

Enterprise-ready access & isolation

From single-team workspaces to multi-org deployments, Vynflow gives you the controls to lock things down without slowing teams down — isolation, identity and throttling built in from the ground up.

  • Username login mode — per-org join-code signup with admin approval, forced TOTP, and org-slug + username sign-in.
  • API rate limiting — per-domain two-tier throttling (per-second and per-hour) on service-account APIs, fully configurable.
  • Row-level access tracking — see who accessed which rows, with analytics over read activity.
  • Secure file sharing — time-limited links, optionally password-protected, that expire on your terms.
  • Workspace isolation — domains never leak data across tenants, with quick switching between the ones you belong to.

Defense in depth

Layered protection across identity, sessions and resources.

  • TOTP & email 2FA with recovery codes
  • Per-domain 2FA enforcement
  • Re-verify sessions on IP change
  • Scoped service-account credentials
  • Configurable per-domain rate limits

Custom roles and IAM permissions are available on Organization plans.

Control who sees what.

Spin up an isolated domain, set access levels, and turn on 2FA in minutes.