Layr logoLayr Docs
Security

Permissions and access

Workspace roles, source selection, and least-privilege access in Layr.

Source selection

Connecting a tool does not ingest everything automatically.

Layr discovers available sources. Sources stay excluded until an authorized user confirms them. Unconfirmed sources are not ingested.

You control which channels, projects, pages, or inboxes are in scope for each connection.

Least privilege

We request least-privilege OAuth scopes for the workflows you enable.

Reading for analysis is the default.

Writing into your tools is a separate, explicit action — for example creating a Jira or Linear issue, or publishing a Notion page from an approved draft.

Workspace roles

Access inside a workspace follows membership roles. The table below summarizes common setup and product capabilities. Exact labels appear in your workspace Team settings.

RoleConnect and manage integrationsConfirm source inclusionInvite teammatesBillingReview queueRead product memory
OwnerYesYesYesYesYesYes
Workspace adminYesYesYesYesYesYes
Product managerNoNoNoNoYesYes
Project managerNoNoNoNoYesYes
Engineering leadNoNoNoNoNoYes
EngineerNoNoNoNoNoYes
ViewerNoNoNoNoNoYes

Review queue and spec drafting are available to the same product-action roles: Owner, Workspace admin, Product manager, and Project manager. Engineering roles and Viewers can read opportunities and product memory but cannot curate candidates or draft specs.

Members who cannot manage integrations still see source freshness on Home when connectors are configured, but they are redirected away from the Integrations page if they open it directly.

Isolation

We isolate customer data by workspace in application access paths and memory search. Normal product use does not cross tenant boundaries.

Learn more

For encryption, AI processing, retention, and deletion controls, see the Security FAQ and Data and privacy.

On this page